ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 178 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
57d863b9-d544-4af5-afbe-268635a8dd98 HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in askapache-firefox-adsense.php in the AskApache Firefox Adsense plugin… wordfence
57cc15a6-2cf5-481f-bb81-ada48aa74009
< 7.2.5
HIGH 8.8 The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
57be67fd-8485-495f-b5e9-6eb52af945b7
< 3.116.0
HIGH 8.8 The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file typ… wordfence
57a39691-8fff-4e62-a03a-70b428025d77 HIGH 8.8 The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page… wordfence
578cf704-e84d-469f-bf26-e60268506a78
< 0.1.0.10
HIGH 8.8 The InstaWP Connect plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.1.0.9 due to… wordfence
578a908a-d447-4b3e-b5d1-be86363c982a
< 3.7.19
HIGH 8.8 In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-th… wordfence
576ca901-45e2-4e6d-9bc4-370bf1f68077
< 5.6.4
HIGH 8.8 The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection via the 'productid' attribute of… wordfence
5716c4e1-a6d3-42e8-b90c-d16f204c8503
< 1.1.4
HIGH 8.8 The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, … wordfence
570474f2-c118-45e1-a237-c70b849b2d3c
< 3.11.7
HIGH 8.8 The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check… wordfence
56fce928-108d-4e59-8746-3699a9db427e
< 3.4.0
HIGH 8.8 The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to… wordfence
56f59303-cf82-4239-9e04-80a32f20d87c
< 2.2.4
HIGH 8.8 SQL injection vulnerability in the Multi Feed Reader prior to version 2.2.4 allows authenticated attackers to execute ar… wordfence
56808590-0226-4968-ba64-0965793a3511
< 2.9.5
HIGH 8.8 The ListingPro - WordPress Directory & Listing Theme theme for WordPress is vulnerable to Local File Inclusion in all ve… wordfence
5658f62b-2f4a-46f7-b229-8e239c7ef148
< 3.1
HIGH 8.8 The Tree Sitemap (Pages, Posts & Categories list) plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… wordfence
56405a91-259c-4700-bbc1-ffe0d77f3974
< 1.3
HIGH 8.8 The Vernissage theme for WordPress is vulnerable to arbitrary option updates due to a missing capability check on the of… wordfence
5607fffa-341f-4237-b064-00fe2e6c9c9f HIGH 8.8 The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an i… wordfence
55bd9bb4-6a81-4e9d-b0a9-76725aba6635
< 2.3.2
HIGH 8.8 The SEO Redirection - 301 Redirect Manager Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
55852490-7087-41b8-9848-758e443ae04b
< 1.13.5
HIGH 8.8 The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action paramet… wordfence
5572fea7-a8d5-457d-88fc-57051b35aa11
< 1.1.1
HIGH 8.8 The JiangQie Official Website Mini Program WordPress plugin before 1.1.1 does not escape or validate the id GET paramete… wordfence
55278cc8-338e-4583-9334-f91f94f22e13
< 4.2.3
HIGH 8.8 The Custom API for WP plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4… wordfence
54fac673-2d83-4d06-a4c0-8bffc269a90c HIGH 8.8 The Media.net Ads Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
54c14f04-32ec-4d05-b47b-3ff5e70c4daf
< 1.3.5
HIGH 8.8 The Houzez CRM plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.4 due to insuff… wordfence
54b3eaf4-5f45-4b94-8a7b-03da76d6ea83
< 2.3.1
HIGH 8.8 The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_med… wordfence
54b2ae17-204f-44cf-bbd3-d012158a4e38 HIGH 8.8 The Writer Helper plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in al… wordfence
549ddee9-9f38-40e2-ac50-bff5366c0b94
< 2.0.14
HIGH 8.8 The Testimonial Slider plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.… wordfence
54852b3d-9830-491d-aa41-bc2bf763a55d
< 4.4.6
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attack… wordfence
← Prev 175 176 177 178 179 180 181 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top