🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 172 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
669df758-0c7d-41c9-a9bd-9b3697898c77
< 20180826
HIGH 8.8 The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta… wordfence
6677aa22-3248-41d5-a257-5330455d5bcc
< 8.18.19
HIGH 8.8 The Book Your Travel theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.1… wordfence
667023f9-9c45-4182-b1f1-9d85d17aaf58 HIGH 8.8 The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is no… wordfence
666c02bd-d3e2-4e40-b189-b73e1136610b
< 1.1.2
HIGH 8.8 An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vuln… wordfence
664eb488-649e-4914-bd3c-cb7395893c6f
< 4.2.0
HIGH 8.8 The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vu… wordfence
6635db72-8302-421d-9011-7eabb57c43a2
< 3.2.7
HIGH 8.8 The Contempo Real Estate Custom Posts plugin for WordPress is vulnerable to unauthorized file uploads due to a missing c… wordfence
66182fc4-863a-4a7b-92a8-2f43717b8579
< 2.8
HIGH 8.8 The Captcha Code plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.… wordfence
65c72e79-f0a9-4293-98be-956d8e4afb83
< 2.1.3
HIGH 8.8 SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated… wordfence
65869722-1147-4fdd-a844-944c51a07f2e HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the Redirection Page plugin 1.2 for WordPress allow remote… wordfence
657b1b7b-eac2-4935-a50f-0849c4e96b16
< 4.8.4
HIGH 8.8 The Download Monitor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation an… wordfence
655b3a54-34b1-4c1a-a1b5-51d87e3134d4
< 1.9.15
HIGH 8.8 The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_in… wordfence
6536d19f-a042-4404-b0c9-91aacd7768f7 HIGH 8.8 The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions u… wordfence
65189c49-600d-4a69-a687-0ff9e327783e
< 1.4.0
HIGH 8.8 The TeraWallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.24… wordfence
64fd32a1-da2a-42db-9597-06366a34f543 HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the Lightbox Photo Gallery plugin 1.0 for WordPress allow … wordfence
64e28272-722d-4a4d-98f6-84e6b29981e3
< 3.1
HIGH 8.8 The BlindMatrix e-Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includi… wordfence
64e21c1c-6c52-4bc8-a399-fa010db60fe9 HIGH 8.8 The Just Post Preview Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… wordfence
64db63e5-ff76-494a-be4f-d820f0cc9ab0
< 10.1
HIGH 8.8 The Information Reel plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a… wordfence
64c72788-a8fa-4f5b-a5b0-8754e952a14d
< 1.1.3
HIGH 8.8 The WP Mail Log plugin for WordPress is vulnerable to SQL Injection via the 'key'’ parameter in all versions up to, an… wordfence
64bae119-12c3-4b3e-88a7-2eb5a7b1b537
< 1.7.7
HIGH 8.8 Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unpr… wordfence
6478cdbc-a20e-4fe2-bbd6-8a550e5da895
< 5.3.2.0
HIGH 8.8 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
646a9885-8e0e-42a9-a113-0688c9f6dc93 HIGH 8.8 The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
645f60ad-c8e5-47ec-94f1-960de4ef7838 HIGH 8.8 The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This … wordfence
642b589d-cb4b-46a0-b9f3-fad8b26bba0e
< 1.6.0
HIGH 8.8 The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks. wordfence
642a8e71-c267-41f5-bcf5-f5627be9038e
< 1.9.0.3
HIGH 8.8 The Csomagpontok és szállítási címkék WooCommerce hez plugin for WordPress is vulnerable to Cross-Site Request For… wordfence
642a6d42-100f-4461-b568-35e089287902
< 3.73
HIGH 8.8 The plugin CRM WordPress Plugin for WordPress is vulnerable to SQL injection via several parameters in versions up to, a… wordfence
← Prev 169 170 171 172 173 174 175 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top