ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 173 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6428cf3c-a784-4e64-a6ef-041b3793ff67
< 6.5
HIGH 8.8 The Hercules Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4 v… wordfence
64196936-a0b8-48a7-ba5c-01ce061df82c
< 1.5.8
HIGH 8.8 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a … wordfence
63f53e3c-b038-4722-b5ba-7212e50b5978
< 2.5.2
HIGH 8.8 The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file wit… wordfence
63d806ed-2cfc-4ac6-9ebb-75c13d2cfad4
< 1.8.6
HIGH 8.8 The Teardrop theme for WordPress is vulnerable to arbitrary option updates in versions up to, and including, 1.8.5. This… wordfence
63af783b-5593-4f84-8a4b-e4a19d9c994c HIGH 8.8 The Admin Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.50. T… wordfence
63a4a077-c99e-4742-9fa1-f323fd24b950
< 2.3.11
HIGH 8.8 The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u… wordfence
6363b693-91b8-41cb-b13a-df6fdf9402c5
< 5.1.3
HIGH 8.8 The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.… wordfence
633d26e9-8a05-4f4b-93a8-5644f2f699db
< 12.7.0
HIGH 8.8 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpf… wordfence
6324795d-3fab-4806-b7d8-f122d31429ff
< 10.8
HIGH 8.8 The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to SQL Injection via the $tid value in versions up t… wordfence
6320cd5f-c5a9-4731-9374-9b8b0838a1ec
< 2.15
HIGH 8.8 A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable main… wordfence
6319ef8c-15ea-4e43-8d46-a6a110cba212 HIGH 8.8 The de:branding plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.2. … wordfence
6305b7be-8651-4028-a8cf-ea58b4977225
< 1.6.5
HIGH 8.8 The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. T… wordfence
62fd2c51-eac1-47c0-adbc-90bdd8dbbc8e HIGH 8.8 The Schreikasten WordPress plugin through 0.14.18 does not sanitise or escape the id GET parameter before using it in SQ… wordfence
62ce7300-4d97-4add-a09d-1f14c99d1c9e
< 5.8.0
HIGH 8.8 The wproject theme for WordPress is vulnerable to Privilege Escalation in all versions up to 5.8.0 (exclusive). This mak… wordfence
629d4809-1dd2-4b67-8d8d-9c55f5240f94
< 1.3.7
HIGH 8.8 Multiple plugins by the vendor E-plugins are vulnerable to privilege escalation due to insufficient restriction on sever… wordfence
6297753c-72c0-4926-9365-d0c760ddfd2a HIGH 8.8 The Yotpo Reviews for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
628eef73-1725-4290-bb30-07792d1d5b6c
< 21.3
HIGH 8.8 The Frontend File Manager plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including,… wordfence
62831b8a-2c6c-44cd-9ed1-f188893bed35
< 1.4.6
HIGH 8.8 The Store Locator WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
6263e0cd-5843-444d-8d12-61a898a77724
< 1.5.5
HIGH 8.8 The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, al… wordfence
624bdb9e-6c50-4a00-9a04-1a32c938d48b
< 1.2.6
HIGH 8.8 The Image Hotspot by DevVN plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi… wordfence
62402e53-ff46-410e-9cc1-a87b677e6526
< 1.6.2
HIGH 8.8 The Role Based Pricing for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … wordfence
61bc71cf-aeaf-4f33-8367-68d5e8ea442c
< 2.8.1
HIGH 8.8 The EazyDocs plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.8.0. This ma… wordfence
61bbd7fe-cacf-4390-b976-3b931fc84af3
< 1.1.5
HIGH 8.8 The bbp-move-topics plugin before 1.1.5 for WordPress has CSRF. wordfence
61992821-a053-4bc6-853a-1a826d096746
< 3.6.4
HIGH 8.8 The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
616c65e7-8d0c-4be8-bd6f-f98187ff1539
< 3.4.7
HIGH 8.8 The User Meta Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on th… wordfence
← Prev 170 171 172 173 174 175 176 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top