πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,577
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,577 vulnerabilities found (page 165 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
76f9d37e-1339-4267-aaf6-38a591e97fa2
< 4.3.6
HIGH 8.8 The WP Database Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
76eff464-69f0-47c1-bdcb-f8caa28a1280
< 0.9.5
HIGH 8.8 In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upl… wordfence
76e4bde3-e815-49c1-9098-c09a54e2274a HIGH 8.8 The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.1. This ma… wordfence
76c39a00-b40a-4d06-96bc-864624e0ef8b
< 7.1.10
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack th… wordfence
76c31190-9db9-4d14-83e0-cbfca812e8ea
< 2.1.4
HIGH 8.8 The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up t… wordfence
76b7a946-71ad-46da-95f6-a02703812938 HIGH 8.8 The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all … wordfence
76ad6d21-f277-496f-aa6b-f9d5cb8a3801
< 3.12.9
HIGH 8.8 The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to … wordfence
767bd8dd-993f-48d3-92f1-669d2329f1ab HIGH 8.8 The Universal Star Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
766e3966-157a-4db3-9179-813032343f76
< 5.3.1.0
HIGH 8.8 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
7638fd24-d376-4b5b-98bb-4a40ada6a4da
< 13.2.11
HIGH 8.8 The WP Statistics plugin for WordPress is vulnerable to SQL Injection via the β€˜limit’ parameter in versions up to, a… wordfence
76044985-477c-4d62-aec3-1905add0a9e2
< 2.5.7
HIGH 8.8 The Duplicate Page and Post, WP Post Page Clone and Duplicate Page plugins for WordPress are vulnerable to SQL Injection… wordfence
75e5e1eb-300f-4ddf-aec5-4fae9dba0f5d
< 2.1.0
HIGH 8.8 The Unlimited Category slider for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… wordfence
75b8f71d-9f75-4b42-ac5f-c6ffb476aae4 HIGH 8.8 The Swifty Page Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
75ac23b7-bcc0-41ce-8cfc-e1de3954d169
< 1.2.2
HIGH 8.8 The Include Me WordPress plugin through 1.2.1 is vulnerable to path traversal / local file inclusion, which can lead to … wordfence
75aa7541-d9d4-4526-9831-238327d0f3ae
< 2.2.4
HIGH 8.8 The Plugin for Google Reviews plugin for WordPress is vulnerable to generic SQL Injection via the $place_id value in ver… wordfence
75a2e8b1-d5e0-4f7b-a70a-f0aadf58c778
< 2.3.6
HIGH 8.8 The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerab… wordfence
758ccfd2-e984-46d9-9643-29299d64940e
< 4.4.2
HIGH 8.8 The My Category Order plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
757938f4-c6ef-4152-a0d6-f14d2a043c85
< 6.10.24
HIGH 8.8 The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
75537b61-5622-4b35-b80e-389526bd99f0
< 4.0.9
HIGH 8.8 The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File … wordfence
74f4068b-224e-4523-9a8d-8713b779a262
< 9.3
HIGH 8.8 The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
74f1966c-f465-4c8f-b7ae-131974961d72
< 3.4.4
HIGH 8.8 The My Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.3… wordfence
74d635b6-2b4a-49af-af5c-6bfa1b5d220e
< 1.2.58
HIGH 8.8 The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the '… wordfence
74b5b09a-33fc-4898-9ead-a7bf47bf7833
< 2.0.1
HIGH 8.8 The Keenarch - Building & Construction WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due t… wordfence
7456ce70-dfa1-46b4-af9e-8185c4f7e5f8
< 1.9.58
HIGH 8.8 The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
74386b2f-9686-4f55-be30-c02ea8fb12b0
< 1.1.16
HIGH 8.8 The LoginPress plugin for WordPress is vulnerable to blind SQL Injection via Settings Import in versions up to, and incl… wordfence
← Prev 162 163 164 165 166 167 168 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top