πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 174 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6158ec37-a6fb-42f9-bab6-bf547ea28ea0
< 3.1.1
HIGH 8.8 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i… wordfence
6145e2d7-c917-4814-a13e-6d34088cb784
< 2.1.1
HIGH 8.8 The WPC Admin Columns plugin for WordPress is vulnerable to privilege escalation in versions 2.0.6 to 2.1.0. This is due… wordfence
60d59753-5b6b-4f3e-8faf-8053750ae05d HIGH 8.8 The AN_GradeBook for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and including, 5… wordfence
60b1abeb-b11a-4de7-b747-53b166276a28 HIGH 8.8 Mufeng's Hermit ιŸ³δΉζ’­ζ”Ύε™¨ plugin <= 3.1.6 is vulnerable to SQL injection. This allows authenticated attackers with… wordfence
609e1177-15aa-476b-b56b-299495055850 HIGH 8.8 The Zegen - Church WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to missing file type … wordfence
609424cf-8bba-4dbd-992f-c48b7283e9f4 HIGH 8.8 The Seo Meta Tags plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4… wordfence
6083c255-48df-498c-ad28-fa8a2e20c67a HIGH 8.8 The Custom Post Type Lockdown plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
6082791e-feac-41f7-b565-9d98624ddf50
< 1.7.33
HIGH 8.8 The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pw… wordfence
60679026-13a3-4702-91a3-876636f3c5bc
< 1.1.7
HIGH 8.8 The Booster Elite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, bu… wordfence
605dae3b-534d-45f3-98bd-150713c34bb7
< 1.5.10
HIGH 8.8 The JetCompareWishlist plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.… wordfence
6045475f-f95a-4618-82ed-e42637d1c1d8
< 1.1.10
HIGH 8.8 The Easy PayPal Shopping Cart for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
603b1f0e-185c-4a0a-a6a2-c63105b2c9f3
< 2.9.1
HIGH 8.8 The Finale WooCommerce Sale Countdown plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… wordfence
603210ca-7231-4c91-8258-fe3cd6e37425
< 1.9.1
HIGH 8.8 The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to … wordfence
6003ad4e-f4ad-49bf-8d83-3da4945456a4
< 2.0
HIGH 8.8 The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… wordfence
6001660c-4b18-473d-a07d-30e0f7af29d1 HIGH 8.8 The DD Roles plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.1. This … wordfence
60013752-d7cf-46e8-84e1-1b614f737b46
< 2.19.26
HIGH 8.8 The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code … wordfence
5fff40e4-6bab-46b4-a6b6-34f89d1aa12c
< 4.2.16
HIGH 8.8 The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to Privilege Escalat… wordfence
5fd0971e-7749-4970-ad39-d0d64a9f1d90
< 2.4.2
HIGH 8.8 The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
5fca3dae-43a9-4130-ad04-8624aeb0c26b
< 1.2550
HIGH 8.8 The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan. wordfence
5f8f8d46-d7e7-4b07-9b10-15e579973474 HIGH 8.8 The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu… wordfence
5f42c8a0-2dbc-4902-83e4-d9d9ea441e1a
< 3.8.12
HIGH 8.8 The Multivendor Marketplace Solution for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
5f2fa602-79db-4bb3-a55c-75da59116f06
< 5.0.6
HIGH 8.8 A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance… wordfence
5f2f34e1-3b08-4e23-a29b-21e61e6a6063
< 2.4.8
HIGH 8.8 The Admin Custom Login plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting v… wordfence
5f24baee-7003-449b-9072-d95fa1e26c8f
< 4.0.25
HIGH 8.8 The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File … wordfence
5ee1bc43-1d9f-4bf7-b5cb-848c6d53938e
< 8.6.5
HIGH 8.8 The MapSVG – Vector maps, Image maps, Google Maps plugin for WordPress is vulnerable to arbitrary file uploads due to … wordfence
← Prev 171 172 173 174 175 176 177 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top