πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 160 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
82df7569-919a-4f95-b0e2-f866133771eb
< 1.5
HIGH 8.8 The User Domain Whitelist plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
82ce66d0-dc53-4433-b499-30bfd48efaf2
< 4.0.10
HIGH 8.8 The Divi Builder, Divi, and Divi Extra plugin and themes for WordPress are vulnerable to PHP Code Injection in versions … wordfence
82c9e3be-a6b8-4d3a-8e1a-cc2e29bb95b6 HIGH 8.8 The Gallerio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ver… wordfence
82b87634-f740-4e4e-bc7e-f8bf7e657486
< 3.5.4
HIGH 8.8 The Emails Catch All plugin for WordPress is vulnerable to privilege escalation via email log exposure in all versions u… wordfence
82960f7a-db21-4e47-a375-473e0b843250 HIGH 8.8 The Hospital Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing… wordfence
8281cb20-73d3-4ab5-910e-d353b2a5cbd8 HIGH 8.8 The WP Popup Banners plugin for WordPress is vulnerable to SQL Injection via the 'banner_id' parameter in versions up to… wordfence
826b3913-9a37-4e15-80fd-b35cefb51af8 HIGH 8.8 The GMAce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This… wordfence
82699a17-ea45-4493-98c4-07f62ca0b1f9 HIGH 8.8 The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and i… wordfence
82246b72-3c29-4574-af86-d0435eecce5d HIGH 8.8 SQL injection vulnerability in the Quartz plugin 1.01.1 for WordPress allows remote authenticated users with Contributor… wordfence
82137302-60ca-44d5-b087-dc96e2815fca
< 5.7.5
HIGH 8.8 The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in vers… wordfence
8202e9e7-b05b-4603-9ebd-8084bf17a230
< 2.54.6
HIGH 8.8 The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks… wordfence
81f025da-c28c-4a80-8b4f-27dae07b2b04
< 3.1.2
HIGH 8.8 The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing f… wordfence
81c80424-3ecb-4740-b458-00a983f35298 HIGH 8.8 The examapp plugin 1.0 for WordPress has SQL injection via the wp-admin/admin.php?page=examapp_UserResult id parameter. wordfence
81a7afc0-05be-4966-b762-081ef553d4e8
< 1.8.7
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the Contextual Related Posts plugin before 1.8.7 for WordPress allows… wordfence
81939cc9-b8f7-4c40-b963-4f6f8c7043e7
< 2.6.26
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the … wordfence
8187c6eb-d962-48a7-bbe8-5949cfdefbce
< 0.4.7
HIGH 8.8 The reSmush.it Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
8185c7a4-3d8e-4a24-9746-536337afbcfe HIGH 8.8 The classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds … wordfence
817ca119-ddaf-4525-beee-68c4e0aac544
< 3.1.24
HIGH 8.8 The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in ver… wordfence
815e5b86-2d1b-4794-b761-dad770393d3e
< 4.8.7
HIGH 8.8 The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulne… wordfence
81330ff8-25a5-403d-abaf-e7c54467abbc
< 5.6.9
HIGH 8.8 The Image Map Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and excluding, 5.6… wordfence
8129046a-5aa5-4644-babc-0eca9aa524d2
< 1.9.4
HIGH 8.8 The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including… wordfence
8108fe83-86fd-4c57-b963-6dad9f50f3f7 HIGH 8.8 The nBlocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.2. This mak… wordfence
8107ed0c-c4eb-4704-9261-4e320e10cdb5
< 1.2.5
HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.5 for WordPress allow rem… wordfence
80f39182-9835-4bd5-b3cd-41fe20983e1e HIGH 8.8 The Filter Custom Fields & Taxonomies Light plugin for WordPress is vulnerable to PHP Object Injection in all versions u… wordfence
80c9f2e3-afdc-4ba2-a1ef-4c1d166d0757
< 2.8.3
HIGH 8.8 The RestroPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.2… wordfence
← Prev 157 158 159 160 161 162 163 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top