ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 166 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
74386b2f-9686-4f55-be30-c02ea8fb12b0
< 1.1.16
HIGH 8.8 The LoginPress plugin for WordPress is vulnerable to blind SQL Injection via Settings Import in versions up to, and incl… wordfence
73fca37e-c6cf-420c-b984-3ef89acf3216
< 2.6.11
HIGH 8.8 The JetElements plugins for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.6.10 vi… wordfence
73e19ad5-97a9-4c0d-a350-eb556bf20772
< 1.3
HIGH 8.8 The Direct Checkout for WooCommerce – Skip Cart with Buy Buttons plugin for WordPress is vulnerable to Cross-Site Requ… wordfence
7392fcb8-f125-4a1e-bb33-5614aeacb4cc HIGH 8.8 The xpinner-lite plugin through 2.2 for WordPress has wp-admin/options-general.php CSRF with resultant XSS. wordfence
73878d57-dd94-41d7-a26a-47c8e6eac0fd
< 1.3.2
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the Related Posts by Zemanta plugin before 1.3.2 for WordPress allows… wordfence
73600498-f55c-4b8e-a625-4f292e58e0ee
< 5.1.2
HIGH 8.8 The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. Th… wordfence
733f7666-468a-455c-a953-3d8946940f13
< 1.4.65
HIGH 8.8 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin instal… wordfence
732c7ccd-de50-4e27-8cb9-3bb0ed30f0b4 HIGH 8.8 The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… wordfence
730a3cde-bcbd-4d60-80bb-3944cc5386e5 HIGH 8.8 The SAM Pro (Free Edition) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … wordfence
72b4fe0f-13cd-4580-9010-1a3e66000251 HIGH 8.8 The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to a… wordfence
7282c9aa-643a-48e7-9b97-09524afca1ba
< 2.2.32
HIGH 8.8 The WPCafe plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.31. This mak… wordfence
722d3fe4-8eb3-451c-9efd-c7daa4a4899f
< 2.2.0
HIGH 8.8 The Team Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.23. Th… wordfence
722c35e5-4084-46a4-a3d4-c73f8e7a1882
< 3.11.2
HIGH 8.8 The Rencontre – Dating Site plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl… wordfence
722c04c3-8f74-4081-b3a4-cb1ae2027312
< 28.4.1
HIGH 8.8 The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is d… wordfence
721d29e4-397d-4965-bd64-33bced8e5de4 HIGH 8.8 The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via … wordfence
71fe1729-4bb5-4b95-9183-b4d793bcfd72
< 1.10.6
HIGH 8.8 The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
71e99412-031e-4f4a-9126-dd3a37975246
< 5.4.2
HIGH 8.8 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Es… wordfence
71e367fb-a663-42ba-9db0-78a436a56205
< 5.0.23
HIGH 8.8 The Download Monitor plugin for WordPress is vulnerable to Local File Inclusion via the get_template_part() function in … wordfence
71dd864f-1975-4cee-be26-0cdb0d54be95
< 4.5.3
HIGH 8.8 The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… wordfence
71c21af1-a007-4535-98ea-a6f25142bcf6
< 4.12
HIGH 8.8 The Accessibility Suite by Online ADA plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in ve… wordfence
71addc0e-c31a-4d61-995a-413c22d1db0c
< 2.1.3
HIGH 8.8 The Customer Switching for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to … wordfence
71a45cd8-4852-4e34-9536-f865e0762b7a HIGH 8.8 The Back Link Tracker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
71415e73-0c7c-4f4a-9322-8d8a1d61c0d4 HIGH 8.8 The WP Edit Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.… wordfence
7110d8f1-8978-494e-afdb-ca96ee503ab7
< 4.1.2
HIGH 8.8 The JTRT Responsive Tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-table… wordfence
710bb2c7-af37-45f4-bede-35ff0d6b90ca HIGH 8.8 The Finance Consultant theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.8 v… wordfence
← Prev 163 164 165 166 167 168 169 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top