πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 169 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6da9514c-a101-4f32-9a2f-697ca9ee1b26 HIGH 8.8 The Blogistic theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ver… wordfence
6d9a3ad3-90fa-46bc-b42a-7616c02a8b50
< 3.3.2
HIGH 8.8 The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file. wordfence
6d881f00-5985-45d5-9aab-d143a010d739
< 2.1.4
HIGH 8.8 The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check … wordfence
6d875c23-3d8a-4f82-bea3-1c46b5045d94
< 2.0.17
HIGH 8.8 The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions… wordfence
6d79ebec-2a80-4b9a-b6d3-f3e9be30047a HIGH 8.8 The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting … wordfence
6d3b9d15-f6a9-4d1c-ada5-8c48add839a2
< 2.8.0
HIGH 8.8 The Bit Form Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all… wordfence
6d3089d3-8ea4-47f7-bbcd-3408a099ae94 HIGH 8.8 The Corsa Theme is vulnerable to Arbitrary File Upload in versions up to, and including, 1.5. This makes it possible for… wordfence
6d27544c-97a5-42cd-ab07-358f819acbc4
< 3.11.0
HIGH 8.8 The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to unauthorized modification … wordfence
6d041edb-70f3-4894-8a78-f6881541054c
< 1.1.8
HIGH 8.8 The Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation in versions up to, and… wordfence
6cc1d7f2-053d-42d4-afb7-6fb69fd71b91 HIGH 8.8 The Banner Cycler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4.… wordfence
6c9aaa7a-d6a7-488f-9800-7e978a765288
< 2.0.0
HIGH 8.8 The Bulk Delete Users by Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
6c7fe504-82b0-4a90-b3a5-cfdafdc1175d
< 1.8.8
HIGH 8.8 The WpTravelly plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8.7. This … wordfence
6c718d65-eb40-43db-821f-344c6eca2384
< 4.3.18
HIGH 8.8 The WP-Appbox plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.3.17 via th… wordfence
6c50568c-c0ec-43f9-bf06-7347f9cfc662 HIGH 8.8 The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, w… wordfence
6c439914-1d5a-4607-8e5c-9279fa3b462c
< 3.11
HIGH 8.8 The Ajax Search Lite plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the… wordfence
6c396ae6-d34c-4554-b670-28868dc136a5
< 1.0.1
HIGH 8.8 The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sa… wordfence
6c338010-9281-44dc-a121-dc2ab5fd6707
< 2.33.1
HIGH 8.8 The PowerPack for Beaver Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i… wordfence
6c18938b-6c0d-461e-b83e-26bc8e7bc1b3
< 6.8.7
HIGH 8.8 The Ask Me theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, but not including, 6.8.7. … wordfence
6bcfc8f1-e962-4ad7-8a9d-89ce5c9022b6
< 2.4.0
HIGH 8.8 The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… wordfence
6bcc8b84-34ac-4f8f-9a74-43b230877e92
< 0.32
HIGH 8.8 The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the… wordfence
6bb785cf-9924-4b47-ac89-5273c6ba8ee6
< 1.0.4
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack th… wordfence
6bb1de69-7bc2-4785-9789-0a2d1cf35b9b
< 5.9.4.6
HIGH 8.8 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in … wordfence
6bb13a69-be75-48f0-9bcc-a33c5add7bd3 HIGH 8.8 The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, wh… wordfence
6b83e971-7e97-47e3-81a5-ff357692bca2
< 3.6.8
HIGH 8.8 The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail… wordfence
6b6b6bc9-2e4b-4a50-9ecb-4311e3555abb
< 2.3.12
HIGH 8.8 The Accordion plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.11 via de… wordfence
← Prev 166 167 168 169 170 171 172 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top