🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 177 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5a9bbe79-a4c3-42eb-8d4d-47d26dbe9f43
< 3.2.3
HIGH 8.8 The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ paramet… wordfence
5a9a496a-7806-426a-a39b-0b236b1d56b5
< 1.1.8
HIGH 8.8 The JetWidgets for Elementor and WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions … wordfence
5a7de576-5809-432f-a6fd-364a3a49967f
< 1.7.0
HIGH 8.8 The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0… wordfence
5a7358cd-fec8-4a16-ae6b-14194bb63396
< 2.9.9.5.1
HIGH 8.8 The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the … wordfence
5a495893-d148-42b7-b029-bc7234e60bc6
< 2.9.1
HIGH 8.8 The aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder plugin for Wor… wordfence
5a425e1c-9b18-468f-975a-57239ce24601
< 3.3.3
HIGH 8.8 The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
59c41620-c6f3-4728-a849-156c5f0ca1a7
< 3.4
HIGH 8.8 The WP Poll Maker – Best WordPress Poll Plugin for Voting Contest plugin for WordPress is vulnerable to arbitrary file… wordfence
59bf14a9-5abe-4b83-9364-d318eedaba83 HIGH 8.8 A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to cross-site request for… wordfence
59b63a01-fd8b-4742-a52f-c0a7b59e9e04
< 21.4
HIGH 8.8 The Frontend File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
5998520b-62fd-4b3d-9b78-6363b72b406d
< 2.0.5
HIGH 8.8 The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. T… wordfence
5988fb74-01d1-426f-9a38-62336a59211b HIGH 8.8 The Post Teaser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.5… wordfence
59859583-49e5-4a80-8659-b9ca7ddc089d
< 2.7.1
HIGH 8.8 The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data … wordfence
5983142d-550f-488f-a2d9-ee552ae8818f
< 1.9.9.5.3
HIGH 8.8 The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… wordfence
596aef67-582a-4506-bae9-c7be1899e47a
< 2.1.10
HIGH 8.8 The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Esca… wordfence
5965a8b6-116e-4029-9a76-b64c03c25ece
< 0.8.8.6
HIGH 8.8 The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page. wordfence
59415c36-e48a-4c05-ad22-8d55a9e13bcd
< 1.4.3
HIGH 8.8 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to… wordfence
59278214-b0ce-44bf-8d8f-265c5c50006a
< 1.58
HIGH 8.8 The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
58fa1235-846f-4bd4-ba0d-be6b039f411e HIGH 8.8 Vulnerability in wordpress plugin rk-responsive-contact-form v1.0.0, The variable $delid isn't sanitized before being pa… wordfence
58cf6e80-63dd-42dc-9c4a-7b5c092bc4cb
< 5.3.1
HIGH 8.8 The ProfileGrid plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the pm_r… wordfence
58b026c8-ad67-4c77-8770-2b3b87bb2dfd HIGH 8.8 The SafetyForms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.0… wordfence
586a4d73-7d3e-4c1d-b369-76f804e555fd
< 2.9.5
HIGH 8.8 The ListingPro theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.4. … wordfence
585fc053-b54f-428e-9abc-9501508aef69
< 1.3.2
HIGH 8.8 The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF. wordfence
58300545-3e53-49be-bf55-eaf3e4cd82e9
< 3.7.35
HIGH 8.8 WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php. wordfence
5804b9da-11cd-4cb4-aa92-2c9e90aa527f
< 3.0.2
HIGH 8.8 SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows re… wordfence
57f56362-da35-44ae-b1f5-4f5a6c21930e HIGH 8.8 The Fileviewer WordPress plugin through 2.2 does not have CSRF checks in place when performing actions such as upload an… wordfence
← Prev 174 175 176 177 178 179 180 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top