πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 182 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4d1512c2-75c1-405b-8bb4-f42ec69159a7 HIGH 8.8 The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
4ce8e0f1-5a7b-41a3-81d0-7fd12c9da6d9
< 3.6.1
HIGH 8.8 The Croma Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal… wordfence
4ccc8f3b-9028-45db-8db2-574736fe3ccb
< 3.1.22
HIGH 8.8 The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 3.1.2… wordfence
4cbbedcb-52dd-44b9-a629-1da0a2552f13
< 1.2.9
HIGH 8.8 The Ovic Responsive WPBakery plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability … wordfence
4c9aabb6-d17c-4845-ae1b-6ee3d8b9bfb1 HIGH 8.8 The SB Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the… wordfence
4c498789-79f4-4b79-8e55-57eab1c51d4e
< 4.5.13
HIGH 8.8 The Redux Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.5… wordfence
4c298a24-b68b-450e-b823-f91841046783
< 9.4.3
HIGH 8.8 The 3CX Live Chat plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 9.4.2 via… wordfence
4be5c7d7-47dd-42ee-9cde-9e9ad6276e41
< 5.2.0
HIGH 8.8 The LayerSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.6.1… wordfence
4bddaefc-9ddc-4798-acb6-7b87f7c924a1
< 1.1.13
HIGH 8.8 The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modif… wordfence
4bc3da9e-4b5f-4200-9df9-0ae953571377
< 7.1.1
HIGH 8.8 The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'por… wordfence
4b8adf59-3bd3-497a-8afd-3df4f7660863
< 4.27.5
HIGH 8.8 The sonaar theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.27.4. This … wordfence
4b475ada-3b31-40a3-9a81-5a7b1a1e190a
< 1.3.1
HIGH 8.8 The Contact Form Entries plugin for WordPress is vulnerable to generic SQL Injection via the plugin's shortcode attribut… wordfence
4b41d134-be9e-469f-b26b-ac30d95db0a3
< 3.7.1
HIGH 8.8 The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injectio… wordfence
4b2fc891-f3c6-4f4f-ad52-0a1a949eed25
< 1.3.0
HIGH 8.8 The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc… wordfence
4b2c3987-fe7e-426d-8398-acdd6fa3a3dd
< 1.0.47
HIGH 8.8 The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all v… wordfence
4b0f5c2c-f01a-4a09-99c2-2b7dfe3bcd05 HIGH 8.8 The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in pl… wordfence
4b0edbf1-bbd2-4e63-86f3-898ad6666d7b HIGH 8.8 The Hospital Management System for Wordpress plugin for WordPress is vulnerable to Privilege Escalation in all versions … wordfence
4b06792e-0b4e-4c1e-b7e9-8cbbae343298
< 1.4.8
HIGH 8.8 The wpCentral for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.4.7 due to missing… wordfence
4aff8870-4222-454a-90cd-044784cb4224
< 1.3.12
HIGH 8.8 The WPSmartContracts plugin for WordPress is vulnerable to generic SQL Injection via an unknown parameter in versions up… wordfence
4af83d4b-2eae-481f-b3fd-d5bcacc1d709 HIGH 8.8 The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in v… wordfence
4af801db-44a6-4cd3-bd1a-3125490c8c48
< 5.38.10
HIGH 8.8 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… wordfence
4af41f69-1335-4199-bf29-c9699de50a16 HIGH 8.8 The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida… wordfence
4adb7436-11e6-4512-b6c9-551402909bf0
< 3.17.1
HIGH 8.8 The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modi… wordfence
4ad5ca1c-b8c3-42c0-8170-821ada826cbb
< 3.7.2
HIGH 8.8 The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.… wordfence
4a76f851-3f4e-4457-a33c-eede51c4b4d1
< 2.0.0
HIGH 8.8 The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in … wordfence
← Prev 179 180 181 182 183 184 185 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top