πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 176 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5c8409c8-8917-4343-a6e6-c6b6be04a236
< 6.3.6
HIGH 8.8 The ChatBot plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.5. This mak… wordfence
5c83457d-ba06-43c5-acdd-77dbfb0d4af4
< 3.5.5
HIGH 8.8 The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
5c5e7ed1-7eb8-4ce7-9dd6-0f7937b6f671
< 2.2.26
HIGH 8.8 The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is… wordfence
5c5b6501-23c5-401b-815d-1729594e6a59
< 2.8.5
HIGH 8.8 The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF. wordfence
5c51f55f-6e8c-467c-999b-4e6a1a6f7bbc
< 4.1.6
HIGH 8.8 The WC Fields Factory plugin for WordPress is vulnerable to SQL Injection via the β€˜post’ parameter in versions up to… wordfence
5c3cefd0-9cbb-4d7a-9fa2-e7a0007fc8b5
< 2.0.29
HIGH 8.8 The Beds24 Online Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2… wordfence
5c3c20b8-12cf-4ce6-a1d4-99204df33fcd HIGH 8.8 The Opt-In Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
5beb0f93-baa7-4400-ab40-d63f3430169e HIGH 8.8 The Events Rich Snippets for Google plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
5be2c2e7-f982-410d-a5dc-f3ef976dff02
< 220502
HIGH 8.8 Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 21… wordfence
5bd58f59-09c2-417c-89ea-5906d413288c
< 7.1.12
HIGH 8.8 The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the… wordfence
5bd06e1e-505d-491e-a92b-61d390c97ea8 HIGH 8.8 The Homepage Product Organizer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via an unknown parame… wordfence
5bbd8851-09ae-40a1-ba88-0a2c439f102d
< 4.0.6
HIGH 8.8 The Ultimate Auction plugin for WordPress is vulnerable to Cross-Site Request Forgery and Cross-Site Scripting in versio… wordfence
5ba5ddf2-8ae2-4bfa-9f15-16425baea6e1 HIGH 8.8 The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which … wordfence
5b92b0a4-7ebf-43b3-837b-ad710e5e35ff
< 1.4.0
HIGH 8.8 The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… wordfence
5b6d0a38-ac28-41c9-9da1-b30b3657b463
< 3.18.2
HIGH 8.8 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Remote Code Execut… wordfence
5b645b88-85e0-4e89-bd95-444ab1db6df8
< 13.5.2.2
HIGH 8.8 The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to… wordfence
5b5e0204-4a05-45c1-833a-c2e4016d9830 HIGH 8.8 The Stockists Manager for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
5b5c8733-7396-4ae5-862d-15db370dbdd7 HIGH 8.8 The Creates 3D Flipbook, PDF Flipbook in WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to m… wordfence
5b37bb5f-7a5f-42bc-bd3b-a5213db29beb
< 1.3.6
HIGH 8.8 The WPC Smart Linked Products – Upsells & Cross-sells for WooCommerce plugin for WordPress is vulnerable to privilege … wordfence
5b313e3d-61e0-496e-af3b-155666fae059
< 3.31.0
HIGH 8.8 The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclos… wordfence
5aef1bc6-b155-4a70-9d08-75951e0725ad HIGH 8.8 The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL state… wordfence
5aeca3b6-6b1b-40b5-8824-de4a90c7ddc3
< 4.1.4
HIGH 8.8 The Gantry Web Theme Framework for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.… wordfence
5ac47137-eecf-4f85-a29d-88a86b2a9c48
< 4.0.4
HIGH 8.8 In the Responsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an admin… wordfence
5ab0d9a2-ca77-439b-bced-8ab5d7b0518a
< 1.8.3
HIGH 8.8 The Manage Notification E-mails plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
5aaf9bb4-bafe-415f-923d-041ef80cabac
< 2.6.2
HIGH 8.8 The Google Doc Embedder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
← Prev 173 174 175 176 177 178 179 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top