🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,415
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,415 vulnerabilities found (page 163 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7b834a3c-6af0-48fd-aa13-985d226b546d
< 1.5.9
HIGH 8.8 The Nextend Facebook Connect plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
7b744385-60ee-4a1a-a6f6-fbdc88f17019
< 4.3.5
HIGH 8.8 The Product Category Slider for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to… wordfence
7b6557de-fd4f-4172-ad7d-940f9f3ea2db HIGH 8.8 The Running Line plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.2 d… wordfence
7b44130c-b526-4670-bde2-e47fe823ac62
< 3.6.5
HIGH 8.8 The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to Cross-Site Request … wordfence
7b2cac27-4a36-490f-b2d8-3c6f32843a38
< 0.2.5.5
HIGH 8.8 The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.… wordfence
7b1242fc-1bbf-4686-ba7d-d948336f65a3 HIGH 8.8 The WP TopBar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.3.2. … wordfence
7b086aec-3af4-4498-bb7d-dd6f6d264be7 HIGH 8.8 Several themes are vulnerable to unauthorized access to functionality in various versions. This makes it possible for au… wordfence
7aca3b02-6c97-4d86-9378-e808c184e84c
< 2.72
HIGH 8.8 (1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.72 for WordP… wordfence
7aa73c13-3f58-423a-ba5f-bebaae2b8371
< 3.7.5
HIGH 8.8 wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote … wordfence
7a9e958f-e53b-4aa0-b7d6-7469852f0d97
< 2.2
HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam … wordfence
7a9846c4-4678-4c25-84fd-b05d21ea34fb
< 8.4.2
HIGH 8.8 The Soledad theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.4.1 due to insufficie… wordfence
7a94229a-6316-48e7-bcaa-23cb2cc047b4
< 2.7.0
HIGH 8.8 The Activity Log plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions 2.3.5 -… wordfence
7a82f52a-0a9a-4b36-960d-f0c7d692c8ee HIGH 8.8 The WP Load Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
7a6b7639-3aaf-44e5-9482-291f8432b41a HIGH 8.8 The Free Stock Photos Foter plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including,… wordfence
7a44d391-63e0-46a5-83fd-5624055705ea
< 1.0.35
HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the Mingle Forum plugin 1.0.34 and possibly earlier for Wo… wordfence
7a027f8f-bec8-456c-804b-b18fdb9532db
< 2.3.1
HIGH 8.8 The ЮKassa для WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
79ef7b33-ea6b-4cf2-bed4-8177927ab650
< 7.4.2
HIGH 8.8 The WPDating plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 7.4.1. This i… wordfence
79dd492e-d4da-4209-83a8-d8059263ae92 HIGH 8.8 The Pexels: Free Stock Photos plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali… wordfence
79dabaa6-d907-4fa6-bc6f-f28f39578256
< 2.6.1
HIGH 8.8 The WP Project Manager plugin for WordPress is vulnerable to SQL Injection via the user task starting date in versions u… wordfence
79b6b896-df66-4c3d-a4d4-d3dbeb630134
< 9.0.3
HIGH 8.8 The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference i… wordfence
79a5c01d-3867-4b1e-b0ba-9a802f0bed92 HIGH 8.8 The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … wordfence
793f27ec-a3bb-4273-a41c-cc5b04c8e8fc
< 2.6.20.1
HIGH 8.8 The JetElements plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.20 … wordfence
792282d1-5f43-4511-becc-9c5bb5ae513a
< 4.1.3
HIGH 8.8 The Simple Membership plugin for WordPress is vulnerable to membership related privilege escalation in versions up to, a… wordfence
79172fe3-c0cf-48c4-8bc5-862c628c1a09
< 6.7.13
HIGH 8.8 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress … wordfence
78da9e79-399e-43e3-ac27-a162861cae71
< 3.4.21
HIGH 8.8 The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable … wordfence
← Prev 160 161 162 163 164 165 166 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top