πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 179 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
547830df-eb90-471b-87be-5c5f2fc52b36 HIGH 8.8 The Rate Own Post plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to insuf… wordfence
5439651e-5557-4b13-813a-4fc0ad876104
< 3.0.5
HIGH 8.8 The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site R… wordfence
542a18f6-9d17-4e54-85e1-e01630ca371e
< 2.14.43
HIGH 8.8 The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and… wordfence
540d1c86-c648-42e1-a360-cc188d1a5635
< 1.2.9
HIGH 8.8 The Gallery PhotoBlocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
53e2f7d5-ceb3-4c15-a761-a9f7c7585358
< 2.3.2
HIGH 8.8 The Conditional Shipping for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
53ab1f5f-7331-4587-8c37-e9bd86a83ae6
< 1.25.4
HIGH 8.8 The Name Directory plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
537bdd21-7ebd-4c17-a681-18703ac973a5 HIGH 8.8 The Image Zoom plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.8.… wordfence
53757567-5024-46cc-b2ae-04b5fc55a35c HIGH 8.8 The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
5361df27-493c-4731-9502-071af4894bbb HIGH 8.8 The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitis… wordfence
535e754e-f851-4809-a148-d9ba808b9d8a
< 9.2
HIGH 8.8 The Wp anything slider plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,… wordfence
535aa061-479f-415e-bee6-3151c42b917e HIGH 8.8 The Configurator Theme Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ… wordfence
53591a3b-8a99-40e2-8145-1d7785bcbab4 HIGH 8.8 The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privil… wordfence
53409aeb-67a6-4a44-993a-fb23f8fb1344 HIGH 8.8 The WooCommerce Extra Cost plugins for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
532ce349-0f4c-4197-bbbd-1e3dcbd0c9d3
< 3.0.8
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.… wordfence
5311b43c-14dd-4bdd-b6d0-d6468b831968
< 3.4.12
HIGH 8.8 The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to privilege e… wordfence
52cce49b-49b3-49b0-9f18-4829f07a420f
< 4.1.3
HIGH 8.8 The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File… wordfence
52b04517-f0be-4bbf-818c-70a12d76bfec
< 3.7.20
HIGH 8.8 The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress is vulnerable to Server-Side Template… wordfence
528a28e7-cdf9-4dfa-b710-8b934863de91 HIGH 8.8 The WPBookit Pro - Appointment Booking Plugin for WordPress plugin for WordPress is vulnerable to arbitrary file uploads… wordfence
527f8f08-bab3-4319-99bf-845c8b378c19
< 1.0.3
HIGH 8.8 The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, … wordfence
5278e8d4-d23e-47ce-b920-dfb7ec56387c
< 1.2.4
HIGH 8.8 The Health Check & Troubleshooting plugin for WordPress is vulnerable to unauthorized execution of AJAX actions by subsc… wordfence
525a2180-3643-4f78-aafd-99a546bac363
< 2.8.0
HIGH 8.8 The Bit Form Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
522b477f-9df9-4d30-aa03-d4946acab21a HIGH 8.8 The WP User Switch plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.… wordfence
52203b9c-7629-4969-8d2d-eb1ef33d160c
< 2.4.2
HIGH 8.8 The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, valid… wordfence
5217c992-4d0d-4774-a404-367e6b6bc47e HIGH 8.8 The Testimonial Slider And Showcase Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an… wordfence
520df463-1ac9-4dbe-b490-8d962757cde7 HIGH 8.8 The Radius Blocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.1. Th… wordfence
← Prev 176 177 178 179 180 181 182 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top