πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 170 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6b155ec8-d69d-40cf-8bea-201629bc9ca6
< 1.0.99.2
HIGH 8.8 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
6ac02888-33e9-43f9-ae10-541133fe4eea
< 1.6.0
HIGH 8.8 The MediaPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.9.1. Thi… wordfence
6abe93e8-b088-49d3-a658-9c6265bfbcdb
< 1.8.8
HIGH 8.8 The All in One Support Button + Callback Request plugin for WordPress is vulnerable to Cross-Site Request Forgery in ver… wordfence
6aaeb0df-75e8-44ac-8964-03e3389d202c
< 2.7.1
HIGH 8.8 The WPBook plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7. This … wordfence
6aa4fd08-a1b1-4f61-a9d1-9812071b61c9
< 0.1.0.9
HIGH 8.8 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to unauthorized modification o… wordfence
6a85fe7f-2d28-4509-99f2-875cb63c6500
< 1.5
HIGH 8.8 The DX Share Selection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
6a5e4708-db3e-483c-852f-1a487825cf92
< 2.6.5
HIGH 8.8 The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.… wordfence
6a42e0e8-a8c7-4bc5-80ca-5ef69d1f0b6c
< 2.3.4
HIGH 8.8 The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3… wordfence
6a3dddda-3a65-42b6-9dc8-760bc3a24dcf
< 3.6.0
HIGH 8.8 The Spreadsheet Integration and Spreadsheet Integration Professional plugins for WordPress is vulnerable to Cross-Site R… wordfence
6a226790-0774-43f6-a476-a2dac7ae153b
< 2.4.0
HIGH 8.8 The Freshdesk (official) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
6a21d834-db8a-471f-b062-59ecfbab0dd6
< 4.0
HIGH 8.8 The [GWA] AutoResponder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
69ffb5fb-16f5-4ef8-81c5-b119da859488 HIGH 8.8 The SEO Backlinks WordPress plugin is vulnerable to Cross-Site Request Forgery via the loc_config function found in the … wordfence
69fa0b8f-8509-47a8-951a-830271b2b29e
< 3.2.4
HIGH 8.8 In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the targe… wordfence
69c7b0e4-89bf-480c-8e89-b1514d2bfefe
< 4.4.9
HIGH 8.8 The WP Meta SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.8… wordfence
69b909da-b1b0-4dab-916c-908511f6556f
< 30.0.3
HIGH 8.8 The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Pri… wordfence
69a9f449-9f94-4da3-9fd0-4eac72b6d8be
< 0.7.0
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to hijack… wordfence
69902627-ce79-4a43-8949-43db6a9cc0dd
< 12.1
HIGH 8.8 The Left right image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in… wordfence
6985e92d-0e7c-409c-a4ab-1edbadad3715
< 9.1
HIGH 8.8 The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
697e9828-2bc9-4732-b564-4cb44a1dc369 HIGH 8.8 The WP Sentry WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could all… wordfence
6973c8e0-d14b-4945-be1c-b7c8b44a4bcf
< 2.11.19
HIGH 8.8 The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin… wordfence
6971eea0-9d0b-4a7f-be05-001c34770c2f HIGH 8.8 The Ping List Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce protection on th… wordfence
694c120a-d9cb-46a6-be24-9f1530bc2183
< 4.2.4
HIGH 8.8 The All in One SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.… wordfence
6942b352-2468-4310-a69c-2590b3b3a4a8 HIGH 8.8 The TAKETIN To WP Membership plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… wordfence
68fe17e2-d5ab-4ebd-a5c6-d65cea327abd
< 1.0.14
HIGH 8.8 The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file upload… wordfence
68f460dc-bb7f-4477-821b-925c7c2c2de5
< 1.8.5
HIGH 8.8 SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allo… wordfence
← Prev 167 168 169 170 171 172 173 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top