πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 167 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7108df0d-771a-4404-b90d-8ac8bc572898
< 2.3.9
HIGH 8.8 The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is… wordfence
71083db7-377b-47a1-ac8b-83d8974a2654
< 1.5.7
HIGH 8.8 The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
70fa060f-11eb-4b51-b985-59421f44414e
< 4.0.9
HIGH 8.8 The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could … wordfence
70eea51c-d4dd-4b9b-a1ad-6077370dec1f HIGH 8.8 The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, w… wordfence
70e1d701-2cff-4793-9e4c-5b16a4038e8d
< 1.6.14
HIGH 8.8 The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to i… wordfence
70d5fccb-a5df-4ffc-a716-f00e6b968b40
< 7.0.6
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the ShareThis plugin before 7.0.6 for WordPress allows remote attacke… wordfence
70d4041e-4b38-4be0-8e51-5a9db4d6c697
< 4.0.4
HIGH 8.8 In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing ma… wordfence
70ce8500-7140-4c97-a91c-55029e67362c
< 2.1.6
HIGH 8.8 The Stars SMTP Mailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
70c144c9-2d96-404d-bcca-707519c9b71c
< 3.4
HIGH 8.8 The WP Content Copy Protection & No Right Click Plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers… wordfence
70bc5247-525d-4aae-9d66-efd65c9beee3
< 4.14.2
HIGH 8.8 The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_pop… wordfence
7087221f-c092-4803-8725-687ffbbbd941
< 1.0.9
HIGH 8.8 The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
704eed2c-5ea8-4c31-99c5-8c1b0572997c
< 2.10.16
HIGH 8.8 An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content f… wordfence
704a60e1-bdb0-498f-a9f1-c9de1c29df7c
< 2.4.2
HIGH 8.8 The stockholm-core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.4.… wordfence
70408046-5eb5-4217-9db4-e7b2a7809cf8
< 4.0.21
HIGH 8.8 The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.20. This ma… wordfence
702cf60a-1d2f-4834-a8ef-96d0026fd81c HIGH 8.8 The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to PHP Object Injection in all v… wordfence
702715a9-b180-4d31-a1df-37b732ae8226
< 4.2.6.9.4
HIGH 8.8 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' p… wordfence
701e6afe-08fa-49c7-a6da-cb266db07c48 HIGH 8.8 The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPre… wordfence
701910b7-6da3-40db-a48b-46a93398953a
< 1.1.7
HIGH 8.8 The Booking Ultra Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
6ff9c202-b3e8-4660-8763-a9fee468203e
< 5.0.5
HIGH 8.8 The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all ve… wordfence
6fde9239-edac-4f85-be12-80825595a332
< 3.8.0.9
HIGH 8.8 The RegistrationMagic - Custom Registration Forms plugin for WordPress is vulnerable to generic SQL Injection via the 'r… wordfence
6fb2d9ec-1082-4209-9fc9-6f10ba3a2398
< 1.7.1
HIGH 8.8 The User Login History for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and … wordfence
6fa560b2-6283-42ab-a482-1e02d08181f8
< 2.7.7
HIGH 8.8 The Paytm Payment Gateway plugin for WordPress is vulnerable to generic SQL Injection via the β€˜post’ parameter in ve… wordfence
6f96b3c4-bec4-4249-9a00-5c21d28d252f
< 1.6.4
HIGH 8.8 The Qode Essential Addons plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1… wordfence
6f853657-1801-4d63-89b8-b2132212a205 HIGH 8.8 The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in… wordfence
6f7742e0-fae8-4fbc-9f98-9374300a528e HIGH 8.8 The Unlimited Elements for Elementor (Premium) plugin for WordPress is vulnerable to arbitrary file uploads due to missi… wordfence
← Prev 164 165 166 167 168 169 170 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top