🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 171 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
68d9aeac-2c01-4afd-8307-906f1bc595d7
< 1.4.5
HIGH 8.8 The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions… wordfence
68c1776e-8e29-4eea-87d0-cf7318a64f7d
< 5.7
HIGH 8.8 There is functionality in the Store Locator Plus for WordPress plugin through 5.5.15 that made it possible for authentic… wordfence
68a80ca3-45f4-4446-af7a-e582c94ccb52 HIGH 8.8 The TotalPoll for Polls and Contests plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, … wordfence
6897a8fe-c32e-430a-847c-23d1add2355d HIGH 8.8 Various Orange themes for WordPress are vulnerable to arbitrary file uploads due to a Cross-Site Request Forgery vulnera… wordfence
6881b0ad-7f11-4709-8c17-37aa505bad4c HIGH 8.8 The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check w… wordfence
687cd0ac-5f78-4429-b6b5-dd1113143a4d HIGH 8.8 The Mobile browser color select plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
68679ff9-48a8-4146-a37f-5f844dc86c92 HIGH 8.8 The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t… wordfence
68366105-996c-4069-978c-c6ff222acd55 HIGH 8.8 The CF7 Reply Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
682b40ad-ca62-47eb-9abc-fd43122d11c8 HIGH 8.8 SQL injection vulnerability in the InLinks plugin through 1.1 for WordPress allows authenticated users to execute arbitr… wordfence
68250b6c-22c8-494f-b0b0-62b80cc4de0c
< 3.3.4
HIGH 8.8 The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress… wordfence
680746a3-8a72-4ec2-9f58-d744f40168ed
< 1.2
HIGH 8.8 The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder theme for WordPress is vulnerable to Remote Cod… wordfence
68023557-fc92-4cf6-96b4-405ff5a5fd5a
< 5.3.3
HIGH 8.8 The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vu… wordfence
67fe46cd-a6c4-4d0a-842a-f61334559731
< 2.3.2
HIGH 8.8 The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Requ… wordfence
67ca3305-9a04-421f-a38e-66b69d2bbd38
< 1.1.3
HIGH 8.8 The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to arbitrary file uploads … wordfence
67c86b04-fdbd-4782-a362-fdec5e1f7c92 HIGH 8.8 The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwan… wordfence
67ae29ee-ec3d-41d2-8691-ba1c615d243d
< 4.2.0
HIGH 8.8 The Meow Gallery plugin for WordPress is vulnerable to Arbitrary Options Update via the REST API in versions up to, and … wordfence
675c86fb-e01f-4957-a49c-31b96383304f
< 1.5.2
HIGH 8.8 SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin be… wordfence
6754ba34-0dc7-40a5-9548-a5f77db0df53
< 3.5.05
HIGH 8.8 The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz… wordfence
673eb0ec-89c2-4d36-91fb-c18a110fe6c4
< 2.4.5
HIGH 8.8 The Restaurant Menu by MotoPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… wordfence
6717adb0-27bc-4cd4-8c34-bea59bc0e016
< 3.5.08
HIGH 8.8 The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Cod… wordfence
66f71de2-055d-42f0-9eb1-145c64f44d5b
< 2.4
HIGH 8.8 The Google Analytics MU plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.4. This is… wordfence
66bd0a9f-66ec-42a5-a123-0a468bb43ed8
< 4.5.0.1
HIGH 8.8 The Advanced Coupons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
66b91fe9-ceb3-485c-bf5f-a672656d4e86
< 2.0.3
HIGH 8.8 The All-in-One WP Migration plugin for WordPress is vulnerable to authorization bypass due to a missing capability check… wordfence
66b7d455-0959-4a7a-b37c-02d1ecac666b HIGH 8.8 The Rotating Posts WordPress plugin through 1.11 does not have CSRF check in place when updating its settings, which cou… wordfence
66afddee-a136-4c71-9e5d-3cc1552010cf
< 5.99
HIGH 8.8 Cross-Site Request Forgery (CSRF) vulnerability leading to Database Reset in WordPress WP Reset PRO Premium plugin (vers… wordfence
← Prev 168 169 170 171 172 173 174 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top