πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 184 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
47e53fd3-4e3f-433a-8e70-3a58c864184a HIGH 8.8 The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and… wordfence
47ccda70-8c89-4e0f-a7fa-5b80515e60dc
< 1.1
HIGH 8.8 The WOWRestro – Online Ordering System For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forger… wordfence
47b75e7f-87d3-40d5-b3c4-998d3164d48a
< 2.6.0.0
HIGH 8.8 The SP Project & Document Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
47a67db6-cc0d-47d2-a2c2-11b8c410f2fb
< 1.5.0
HIGH 8.8 The Designer plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.1. This ma… wordfence
473ba791-af99-4aae-99cb-ccf220e443e7
< 5.5.2
HIGH 8.8 The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
4729ed37-96b2-4717-8a72-89b9a21ec058
< 1.24.12
HIGH 8.8 The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions… wordfence
471957f6-54c1-4268-b2e1-8efa391dcaec
< 3.2.50
HIGH 8.8 The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]… wordfence
46c40aed-1df9-4c20-9058-1ae62864fc9d HIGH 8.8 The Advanced Booking Calendar for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
46c0fa1e-f400-435c-b781-23919a192e89
< 1.9.9.5
HIGH 8.8 The WPLMS plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.9.9.5 (exclusive). This ma… wordfence
469a702f-033a-40de-b725-b0ad4f8e92e8
< 1.0.2
HIGH 8.8 The Ship To eCourier plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
468fc0c3-288d-4d9c-a27a-68470f220c39 HIGH 8.8 The Image Gallery Box by CRUDLab plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… wordfence
4681e56f-1dad-46a7-8ac7-1f543a383433
< 1.0.16
HIGH 8.8 The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu… wordfence
4678d2a3-8f8d-488a-8d2b-6c321b96eb36 HIGH 8.8 The WP Quick Setup plugin for WordPress is vulnerable to unauthorized plugin and theme installation due to a missing cap… wordfence
4654609e-ed3e-4268-a9a4-80bc563e0a64
< 3.2.49
HIGH 8.8 The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
46226921-a445-4fb7-9c90-bd2d6841dec7 HIGH 8.8 The Tracked Tweets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.… wordfence
46039930-377e-4adb-8d96-09ebf220b4a6 HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the Sliding Social Icons plugin 1.61 for WordPress allow r… wordfence
45eda79d-f999-413e-88ce-b7d06f09f191 HIGH 8.8 The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request F… wordfence
45eac3e1-db31-4d3d-844f-ae106b9eee7a
< 1.1.5
HIGH 8.8 The MetalpriceAPI plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.1.… wordfence
45d7732f-cdcd-4cef-a01e-22e06566e8a1 HIGH 8.8 The PowerFormBuilder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.6 due to … wordfence
45a62dd0-386c-41b3-b8dd-ced443da9f92
< 2.9.4
HIGH 8.8 The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and inclu… wordfence
45a42f20-a4d7-4c8e-a144-505a6723a2a0
< 2.1.1
HIGH 8.8 The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
45816c45-42bc-4163-b700-a1e913f32c97
< 3.6.6
HIGH 8.8 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request… wordfence
45668368-5846-41bb-b862-dfeb283e83cf
< 7.6.7
HIGH 8.8 The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to privi… wordfence
455b9695-e140-4bdb-b626-5c1695518563
< 4.1.3
HIGH 8.8 The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File… wordfence
452e9acc-4029-4f43-9941-c1aa2a413e34 HIGH 8.8 The Lean WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. Th… wordfence
← Prev 181 182 183 184 185 186 187 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top