πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,412
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,412 vulnerabilities found (page 164 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
788bf199-bf09-4076-b5f1-129b6287096a
< 0.9
HIGH 8.8 The Most Popular Posts Widget plugin for WordPress is vulnerable to SQL Injection via the 'PostID' variable in versions … wordfence
7886708a-8daa-465b-b820-53bf409e682c
< 4.2.1
HIGH 8.8 The Tidio Live Chat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… wordfence
78669d4f-3c1e-49e6-af8d-56f105f99d01
< 1.5.1.2
HIGH 8.8 SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arb… wordfence
784593ec-b635-4f59-9afb-ab506f786d21
< 2.1.3
HIGH 8.8 The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
782d0920-08dd-4df7-958c-3ed7128f3d55
< 1.5.2
HIGH 8.8 The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file… wordfence
77e4e516-8a12-48ee-9124-27f941b68b13
< 4.1.1
HIGH 8.8 The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, … wordfence
77de0955-d6e4-4da0-8a71-772c404e5dc2
< 4.3.0
HIGH 8.8 The WP OAuth Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… wordfence
77b7fb02-1b79-4b0b-99ab-fa042e86391a
< 2.2.8
HIGH 8.8 The Meta Data Filter & Taxonomies Filter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions ve… wordfence
77a2d64f-852f-4cc2-9905-98c8f0930817
< 1.2.2
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the aut… wordfence
778f7d9b-6376-4026-a291-1fedeabe8c99 HIGH 8.8 The Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3 via des… wordfence
7762fe69-9bd4-4e4e-a6c5-1263fad352a0 HIGH 8.8 The Hacklog DownloadManager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
775e9f94-b66d-4c22-81ef-c335c0654f08
< 3.4.1
HIGH 8.8 wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order… wordfence
774afb96-4385-4693-a446-c87f81b39feb
< 2.3.4
HIGH 8.8 In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could… wordfence
772e17d6-2819-4e66-88f2-0c7a6c0aaff0
< 2.23.1
HIGH 8.8 The Quform - WordPress Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… wordfence
77189684-b794-41a0-8fc0-3320032c2f69
< 3.1
HIGH 8.8 The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
76fb7f1d-4f41-4a73-acbf-c0f49f0123b4
< 1.3.13
HIGH 8.8 Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote atta… wordfence
76f9d37e-1339-4267-aaf6-38a591e97fa2
< 4.3.6
HIGH 8.8 The WP Database Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
76eff464-69f0-47c1-bdcb-f8caa28a1280
< 0.9.5
HIGH 8.8 In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upl… wordfence
76e4bde3-e815-49c1-9098-c09a54e2274a HIGH 8.8 The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.1. This ma… wordfence
76c39a00-b40a-4d06-96bc-864624e0ef8b
< 7.1.10
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack th… wordfence
76c31190-9db9-4d14-83e0-cbfca812e8ea
< 2.1.4
HIGH 8.8 The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up t… wordfence
76b7a946-71ad-46da-95f6-a02703812938 HIGH 8.8 The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all … wordfence
76ad6d21-f277-496f-aa6b-f9d5cb8a3801
< 3.12.9
HIGH 8.8 The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to … wordfence
767bd8dd-993f-48d3-92f1-669d2329f1ab HIGH 8.8 The Universal Star Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
766e3966-157a-4db3-9179-813032343f76
< 5.3.1.0
HIGH 8.8 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
← Prev 161 162 163 164 165 166 167 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top