🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 180 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5205cc95-06d1-4bc6-a9ea-082df9566935
< 1.1.4
HIGH 8.8 The WP Blog Post Layouts plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including… wordfence
51fe2379-e5c6-4cd0-b7d1-b03105403b97 HIGH 8.8 The SK WP Settings Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
51d4b7f6-183b-4a8d-a94d-83c66950a872
< 2.1.0
HIGH 8.8 The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Esca… wordfence
51d0ba58-614e-4284-ae0b-b0b76fc5c46d
< 43.3
HIGH 8.8 The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43… wordfence
51cf2f40-7be8-4302-a766-88ec2f0501f5
< 3.4.1
HIGH 8.8 includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF. wordfence
51cd2cb8-ac77-4962-9156-da0195ce1003 HIGH 8.8 The BuddyForms plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.8.17. This… wordfence
5184740a-c747-4217-bb13-6568465672df
< 1.4.3
HIGH 8.8 The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions… wordfence
517531ec-4160-4287-8499-6266e08223dc
< 4.2.1
HIGH 8.8 The Classified Listing plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.… wordfence
51634a0c-f979-403b-80b0-8e3a65e7ad35 HIGH 8.8 The FAQs Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… wordfence
516261b5-4356-40e1-9418-3243086bc1b4
< 3.4
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers … wordfence
515a5dfd-c064-47d2-b347-e4f417bb260a
< 1.0.16
HIGH 8.8 The QuickCal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.15. … wordfence
515502b5-c344-4855-aff1-57833233c5d2
< 8.1
HIGH 8.8 The Wp photo text slider 50 plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions u… wordfence
5143a2d2-504a-46b8-b82b-19beba4da64d
< 2.0.22
HIGH 8.8 The Arbitrary File Upload plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including,… wordfence
5137244c-584f-4b48-869a-b6669c84eaac
< 1.1.6
HIGH 8.8 The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with result… wordfence
5118ed50-d7be-4606-af9d-18b63359956c
< 8.2.7
HIGH 8.8 The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape… wordfence
50bc789a-be96-4e65-9a1d-0314c0247613 HIGH 8.8 The Smallerik File Browser plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
50adbe1d-9d79-4015-9e09-2166f97efc47 HIGH 8.8 The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missin… wordfence
50946bc7-8d31-4376-bdcc-de7aad700503
< 1.0.8
HIGH 8.8 The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress is vulnerable to Privilege Escalation… wordfence
50932c88-994d-4904-b075-e48d2cb5bc24
< 1.3
HIGH 8.8 The Add Multiple Marker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
50812a8b-7d49-41fa-ba50-47d07a4b6caa
< 4.1.2
HIGH 8.8 The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently plugin for WordPress is vulnerable to PHP Obj… wordfence
507d308e-7df7-4bcb-b63c-f438b482c36b HIGH 8.8 The Post Index WordPress plugin is vulnerable to Cross-Site Request Forgery via the OptionsPage function found in the ~/… wordfence
507c2abd-47d3-4a28-a9b7-a1ad9b026e7d
< 1.6.4
HIGH 8.8 The Nokri - Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in … wordfence
506d1518-658f-4deb-9c30-d0bce5ef9df4
< 3.7.28
HIGH 8.8 WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca… wordfence
502724d9-ccc4-42db-bc1e-c521f7c80e70
< 3.3.3
HIGH 8.8 The Profile Builder/Profile Builder Pro plugins for WordPress is vulnerable to blind SQL Injection via multiple paramete… wordfence
501fb05a-c8ec-43c6-b462-2a83c4f8b6b7 HIGH 8.8 The LiveSync for WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could … wordfence
← Prev 177 178 179 180 181 182 183 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top