πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 175 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5eafb620-f5dd-4e60-b9a6-859832ae706c
< 5.6.3.3
HIGH 8.8 The Integration for Szamlazz.hu & WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… wordfence
5eaac50c-c585-4587-91b7-9d0613345ef2
< 6.8.4
HIGH 8.8 The Ask Me theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.8.3. This… wordfence
5ea53fb7-9bf8-445b-ad33-f3b6e6ed1665
< 6.3.6
HIGH 8.8 The Complianz plugin for WordPress is vulnerable to SQL Injection via unescaped translations in versions up to, and incl… wordfence
5e8c06c7-dbe0-4b2b-99bc-89f18277e540
< 1.4.2
HIGH 8.8 The Export WordPress Data with Advanced Filters plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers… wordfence
5e78ec78-61e0-4c99-9e73-89fc6606fb97
< 1.2.42
HIGH 8.8 The Photo Gallery plugin before 1.2.42 for WordPress has CSRF. wordfence
5de8b93a-d7b1-4679-8c3c-2ac099a1f58f HIGH 8.8 The XforWooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0… wordfence
5dce15ea-70cf-4b4c-959a-8adf2cdcdca4
< 7.4.2
HIGH 8.8 SQL injection vulnerability in social-slider-2/ajax.php in the Social Slider plugin before 7.4.2 for WordPress allows re… wordfence
5db5ea76-f0b6-4e30-aebf-c3769d0b3480
< 1.7.9
HIGH 8.8 The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF. wordfence
5db5c5e0-f2ba-4082-b3eb-33cc0ce418e8
< 3.1.24
HIGH 8.8 The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to generic SQL Injection via the β€˜id’ para… wordfence
5db42c7e-49bc-48ee-8129-b8a0df0c8d98 HIGH 8.8 The Forms by CaptainForm plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
5d82e9e2-c572-4911-a6a5-1384844214b0 HIGH 8.8 The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including… wordfence
5d7fb9fd-5551-43aa-8bab-e99430a08124
< 2.1
HIGH 8.8 Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote… wordfence
5d762b22-5563-454f-8c1c-485a2a3a0d0f HIGH 8.8 The Tracked Tweets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.… wordfence
5d5d9ef7-3832-495c-b61b-7e24c2e60893
< 0.4.4
HIGH 8.8 Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer… wordfence
5d4bd61c-858d-457f-a482-77939fe0caf9 HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in adsense-deluxe.php in the AdSense-Deluxe 0.x plugin for WordPress all… wordfence
5d2f07bb-89b3-41d4-b606-9722deecf816
< 9.17.0
HIGH 8.8 The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missi… wordfence
5d22435f-f0e3-42c3-935b-d26bb1ea846a
< 1.6.3
HIGH 8.8 The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is a… wordfence
5d166a77-d57b-4827-96ca-b8eb423861f0
< 6.23.4
HIGH 8.8 The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized modification of data … wordfence
5d096d29-6fdb-4f89-91d3-9ebfc1169f0d
< 4.0.7
HIGH 8.8 The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it i… wordfence
5cfe9ab3-45b8-4ee5-9de1-45182a4fc46f
< 2.0.2
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in OG Tags versions prior to 2.0.2 allows a remote attacker to hijack th… wordfence
5cf6a9fb-3c3b-48ad-a39b-77a529b89901
< 3.0.0.2906
HIGH 8.8 The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. … wordfence
5cd5e6f3-b791-48a8-b7eb-42cdd8975530
< 1.9.15
HIGH 8.8 The Rich Reviews by Starfish plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
5cbbce9e-bfb5-49b3-9829-1f90e0d8f517
< 2.1.1
HIGH 8.8 The WP User Groups plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
5cbb8495-70e0-48cc-84d9-6d3cf3ec5355
< 1.0.3
HIGH 8.8 The WebP Converter for Media – Convert WebP and AVIF & Optimize Images plugin for WordPress is vulnerable to Cross-Sit… wordfence
5ca35c9d-a7e0-4442-82d5-5040a3443c2b
< 3.15.5
HIGH 8.8 The Avada (Fusion) Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi… wordfence
← Prev 172 173 174 175 176 177 178 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top