πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 168 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6f721aa1-d12f-4829-8e82-61f9af6a3519
< 3.3.3
HIGH 8.8 The Simple Membership plugin for WordPress is vulnerable to multiple Cross-Site Request Forgery attacks in versions up t… wordfence
6f6aa094-6bac-463f-b46d-c65f591abbb3
< 3.7.40
HIGH 8.8 WordPress Core is vulnerable to SQL Injection in the Media Library that can be leveraged to exploit a Reflected Cross-Si… wordfence
6f63d2c4-cbae-4177-8494-daca96449ecc
< 2.5.16
HIGH 8.8 The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPres… wordfence
6f526959-be34-48d1-8aa1-e36f7708bd20
< 2.3.16
HIGH 8.8 The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id param… wordfence
6f36d866-aa94-478b-8b62-0906bc95e413
< 6.2.1
HIGH 8.8 The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
6f359d02-d4ce-4045-9e79-ae0f92b84766
< 4.64.4
HIGH 8.8 The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
6f1a1acc-6144-4e91-b552-240a505fad0f HIGH 8.8 The Training – Courses plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… wordfence
6f099519-0ebc-45f5-93a9-2b32d51c874f
< 1.9.9.1
HIGH 8.8 The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to unauthorized modi… wordfence
6f00dfd7-3194-4459-b895-f16d3aa8d66f
< 1.3.2
HIGH 8.8 The Responsive Image Slider, Photo Gallery And Carousel plugin for WordPress is vulnerable to Cross-Site Request Forgery… wordfence
6f00bbab-ef84-42cf-baa7-23c434416981
< 8.6.5
HIGH 8.8 The Geo Controller plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 8.6.… wordfence
6ed215da-10c5-469b-bab2-923808feebd4
< 6.10.0
HIGH 8.8 The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data… wordfence
6eccf601-ad95-4fb5-a3a6-e916df6a6b56
< 1.8.7
HIGH 8.8 The Slider by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
6eb76b6a-142e-4918-b4f7-77debbf1b75c
< 1.2.7
HIGH 8.8 The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to,… wordfence
6eb6611d-7a4b-4ca8-b9cc-c156437e89b5
< 1.7.3
HIGH 8.8 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
6eb23014-7bc6-4505-85d7-91d29bb2d8fb
< 6.5.12
HIGH 8.8 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin befo… wordfence
6e953bc0-a934-43fc-8147-4555dde069cc
< 1.0.1
HIGH 8.8 The GA Universal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.0.1. This is due … wordfence
6e327239-b4f0-4d21-b25e-f015498981cb HIGH 8.8 The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is v… wordfence
6e31c347-aca4-4c1f-8456-53225f6b677b
< 3.1.2
HIGH 8.8 The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to arbitrary file deletion… wordfence
6e0e8f5f-8216-4276-a810-860f9b52c447
< 1.9
HIGH 8.8 The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import… wordfence
6ded39db-90d7-4818-afa0-697ffe3bf1db HIGH 8.8 The Themify Edmin theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.0 via … wordfence
6de73c31-a58d-41d9-aaed-2d7853ad1f25
< 6.9.10
HIGH 8.8 The Blog2Social plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.9.9 due to insuf… wordfence
6de6e95b-3ea3-4078-96cc-687d4f1191e8
< 2.1
HIGH 8.8 The Catch Dark Mode plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.1. … wordfence
6ddf0452-3afe-4ada-bccc-30c818968a81 HIGH 8.8 The Simplr Registration Form Plus+ plugin for WordPress is vulnerable to Insecure Direct Object References in versions u… wordfence
6dc9b4cb-d36b-4693-a7b9-1dad123b6639
< 1.44.3
HIGH 8.8 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrar… wordfence
6dc2e720-85d9-42d9-94ef-eb172425993d
< 4.68
HIGH 8.8 The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up… wordfence
← Prev 165 166 167 168 169 170 171 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top