ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 183 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4a6e5f89-ebc0-413a-a76e-3cf4339430ba HIGH 8.8 The TerraClassifieds plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
4a64f840-8570-4f98-8b72-27bee1607fc2 HIGH 8.8 The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5… wordfence
4a56a838-5dfa-477a-92b2-fdac3d1ab2af
< 1.1.7
HIGH 8.8 The Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
4a4f0909-76f6-4d27-87b1-f6cd5f5cbbb7 HIGH 8.8 The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.… wordfence
4a4c085a-1601-4c1a-ac17-0f2cf5d02489
< 1.4.3
HIGH 8.8 The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
4a40ddbc-0b9a-40bd-bf68-9e63723acb1c
< 1.1.8
HIGH 8.8 The XT Event Widget for Social Events plugin for WordPress is vulnerable to Local File Inclusion via the render_facebook… wordfence
4a2ca2f0-1d4a-4614-86ba-a46e765f4a9f
< 1.7.6
HIGH 8.8 The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' param… wordfence
4a249c93-c029-44c1-8563-8adf1e2e3062
< 1.11.13
HIGH 8.8 The immonex Kickstart plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.11.… wordfence
49eaee21-15c0-4c43-857d-05f0993509ea
< 1.1.1
HIGH 8.8 The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, an… wordfence
49b296a5-8721-4835-b2c1-ab45045be595
< 2.3.6
HIGH 8.8 The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php. wordfence
499059b9-44c0-40da-bc45-5280ea84f016
< 6.5.2
HIGH 8.8 The WP Travel Engine plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.5.1.… wordfence
49754f41-b809-4a97-ab8f-233f51dc058f
< 1.5.64
HIGH 8.8 The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via ajax actions, by exploiting following WP ajax a… wordfence
49209249-11c7-4839-9fa4-423f09008bdc
< 8.5.27
HIGH 8.8 The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to arbitrary f… wordfence
4915b769-9499-40ac-835e-279e3a910558
< 3.19.1
HIGH 8.8 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to arbitrary file del… wordfence
48f5aba0-42a0-4b63-8195-29103576a794 HIGH 8.8 The RS-Members plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.3. T… wordfence
48c6efc9-6c53-4ac9-8f99-62fbab0599ce
< 3.0.330
HIGH 8.8 The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to blind SQL Injection via the ‘delete… wordfence
4891fd3f-563b-497a-a5d9-617f4862298b
< 1.8.7
HIGH 8.8 The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_… wordfence
488970f0-3120-4f4a-9915-2ae1708bd86a
< 3.6.10
HIGH 8.8 The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cros… wordfence
487d4175-97bf-4c65-9d7d-b83974e9fda9
< 5.3.0
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote at… wordfence
486fa1a6-aa47-4bf9-b1da-582e316f6bcb
< 26.5
HIGH 8.8 The Woocommerce Customers Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability… wordfence
48658b33-ae53-4919-8180-1188f72553f7
< 1.0.16
HIGH 8.8 The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both t… wordfence
482bae65-5493-4de5-9d5f-479d0968cd4a HIGH 8.8 The Launchapd plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.13.… wordfence
4824be4c-eec0-4979-85e1-6c692b3a8243
< 2.0.4
HIGH 8.8 The Post/Page Copying Tool to Export and Import post/page for Cross site Migration plugin for WordPress is vulnerable t… wordfence
48069ad5-0779-444b-8215-d1f08b493108
< 9.1
HIGH 8.8 The SEO Redirection Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
47fb0513-bebe-4e09-9402-d7e174ee92ce
< 2.0.66
HIGH 8.8 The NextGen Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
← Prev 180 181 182 183 184 185 186 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top