πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 159 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
851ff861-474e-4063-88ff-d8d35b10e9a0
< 1.1.6
HIGH 8.8 The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable… wordfence
84ffb581-cd59-41df-a6c5-8b2a5923e900 HIGH 8.8 The Miion | Multi-Purpose WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to missing fil… wordfence
84f2afb4-f1c6-4313-8958-38f1b5140a67
< 8.4.2
HIGH 8.8 The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. Thi… wordfence
84b609a5-d3d6-4a30-b55e-7f7972c64ccb
< 4.1.6
HIGH 8.8 The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
8494a0f6-7079-4fba-9901-76932b002c5a
< 6.1.8
HIGH 8.8 The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Inject… wordfence
84936b68-923a-4da1-ae67-1d63d025342e
< 1.7
HIGH 8.8 The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitr… wordfence
84888ea6-122d-4480-8262-d87c33113bd7
< 4.6.1
HIGH 8.8 The EELV Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… wordfence
8475dd90-b47a-42b4-8e4e-44e8512e4fca
< 4.0.0
HIGH 8.8 The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Exe… wordfence
8459c436-0c4d-40e6-a30d-94b8ac50df83 HIGH 8.8 The WooCommerce Custom Registration Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
8429148b-e28e-4bb3-bd18-390216b74dc4
< 1.3
HIGH 8.8 The Request for Quote plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.3. This is d… wordfence
84227fd2-c322-45e3-82cd-70e1d870eceb
< 0.9.4.1
HIGH 8.8 The W3 Total Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.… wordfence
840e9a50-ce53-4b9a-b6ae-c5016e11373b
< 2.4.5
HIGH 8.8 The WP Maintenance Mode & Coming Soon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
83f6c9fb-4ee7-42c0-9369-a0d577dd485f HIGH 8.8 The 3D Work In Progress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path vali… wordfence
83f6bdda-e489-4e85-b510-7bfaa2329609
< 1.6.6
HIGH 8.8 The Page Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
83e53dc4-84fe-4835-aaea-b72dfe8f7475
< 1.2.5.6
HIGH 8.8 Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability tha… wordfence
83d69f7b-0f98-43d3-baef-51216e26d357
< 6.3.6
HIGH 8.8 The WP Travel Engine plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.5.… wordfence
83d4f114-c113-4c66-be74-2d438aa00502
< 1.5.0
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the Add/Edit page (adminmenus.php) in the WP125 plugin before 1.5.0 f… wordfence
83c0e096-f054-4367-a85f-582c0771e3fe
< 1.0.5.3
HIGH 8.8 The Becustom plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5.2.… wordfence
83a595b7-379c-4202-abdd-d8ba4a30c6a4 HIGH 8.8 The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to PHP Obje… wordfence
83a58119-d0ed-47fe-93d1-1aa1def2cf44
< 4.0.2
HIGH 8.8 The Streamit theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'st_… wordfence
839a0cc0-a656-4107-a748-4ad85e950237
< 1.8.2
HIGH 8.8 The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … wordfence
839957ea-5186-4cce-971d-57eed84639d5
< 3.8.5
HIGH 8.8 The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section. wordfence
8376556e-ed78-4a0e-a23f-9b2a39db94d9 HIGH 8.8 The Photo Video Gallery Master plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… wordfence
835579b0-8a96-40fa-a6a3-30571a0a1d0a
< 1.13.0
HIGH 8.8 The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… wordfence
832af296-7d7c-47a0-84a4-01a1fe78ff21
< 7.8.8
HIGH 8.8 The Cornerstone plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 7.8.8 (exclusive). Thi… wordfence
← Prev 156 157 158 159 160 161 162 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top