πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 181 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4fc00e00-5015-4dd7-8b26-56f3925bdbc6
< 2.6.1
HIGH 8.8 The DELUCKS SEO plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.0. … wordfence
4f8a7933-cc26-47f2-9142-df748add0745
< 3.3.1
HIGH 8.8 The Auto Upload Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
4f8430e8-c349-4425-be4a-0e9d4d80c438
< 1.2.4
HIGH 8.8 The MaxSlider plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.3. Th… wordfence
4f73ef2a-8e78-4091-bc78-f6b35444e677
< 1.3.0
HIGH 8.8 The Subscribe to Download Lite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includi… wordfence
4f5e0d47-ad38-4081-8dfc-d782aef4bf0c
< 4.19
HIGH 8.8 The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to arbitrary file uploads due to missing file… wordfence
4f3f0ef8-8a13-4110-a402-e1bcf493560a
< 2.12.23
HIGH 8.8 The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to SQL… wordfence
4f0deb68-3caf-4ad6-977e-0e954d29e6b7
< 4.6.2
HIGH 8.8 The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parame… wordfence
4f033d5d-d76b-4c63-80bc-32fdd0e7987e
< 1.7.3
HIGH 8.8 Eval injection vulnerability in the fm_saveHelperGatherItems function in ajax.php in the Form Manager plugin before 1.7.… wordfence
4ef1a097-955c-4a0e-a1a2-b34ae2903d0e HIGH 8.8 A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads… wordfence
4eeed189-3c57-4f23-bb6c-3e84603a83fb
< 3.43
HIGH 8.8 The WP Tools plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.41. This is… wordfence
4e7f72d8-beef-4304-8d05-4741fb6165b1
< 3.2.0
HIGH 8.8 The Advanced Settings 3 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
4e6654b6-90ae-4a5e-bff3-82848813872a
< 4.0
HIGH 8.8 The WP Page Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.… wordfence
4e479a3f-ef1a-4476-89e1-86d0f388f2c3
< 2.2.58
HIGH 8.8 The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX… wordfence
4e3fa273-383a-46ac-8525-5508aaf33424
< 1.5.1
HIGH 8.8 The A1POST.BG Shipping for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
4e3da1d3-5ec3-4f94-a834-3f3a6fc23f0a
< 1.0.7
HIGH 8.8 The JS Job Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
4e337281-f05e-486c-9491-161365af252a
< 1.6.5
HIGH 8.8 The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to m… wordfence
4e0d21e6-d8a2-44ab-87f3-9e5a16562020 HIGH 8.8 The Oceanwp sticky header plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
4dc6e879-4ccf-485e-b02d-2b291e67df40
< 1.3.8
HIGH 8.8 The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all ver… wordfence
4dac404d-369c-4036-9c64-4afab021cbe8 HIGH 8.8 The Lenxel Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.5. This… wordfence
4da18aad-3c82-4bc6-8dad-523643c12d5b
< 1.4.4
HIGH 8.8 The WP Testimonials plugin for WordPress is vulnerable to SQL Injection via the 'widget_id' parameter in all versions up… wordfence
4d805963-a36c-41a1-aa03-0dc29b9216ff HIGH 8.8 The Nice Backgrounds plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, … wordfence
4d6ea02d-df63-476c-b205-fa64ada18db5
< 4.3.0
HIGH 8.8 The WP Helper Premium plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.2.0 due to… wordfence
4d6ddee9-d9c3-4cea-85f1-a1ddd101aac1
< 3.7.1.3
HIGH 8.8 The BadgeOS plugin for WordPress is vulnerable to SQL Injection via some of its ajax actions in versions up to, and inc… wordfence
4d5fe67d-1ac3-44f0-a1dc-45ec4bd2de74
< 2.4.2
HIGH 8.8 The EventON plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.1. This mak… wordfence
4d260dd3-0006-4a2d-b7ca-c484e4c9ebb5
< 8.0.2
HIGH 8.8 The Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools plugin for WordPress is vu… wordfence
← Prev 178 179 180 181 182 183 184 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top