🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 185 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
44e71dea-d736-49c2-a630-f42905ac6b4d HIGH 8.8 The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t… wordfence
44c5a1cd-aac2-4c44-8aaa-9b5fdafad133
< 1.3.3
HIGH 8.8 The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id paramet… wordfence
44b259c7-ea91-4ab5-a46b-67aec50654c3 HIGH 8.8 The SEO Scout plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.9.83 … wordfence
449dfb1b-cd06-406f-82d5-c615383a0409
< 2.0.1
HIGH 8.8 The Wiguard – CCTV & Security WordPress Theme for Surveillance Companies theme for WordPress is vulnerable to arbitrar… wordfence
4488d982-4e57-4614-b336-f1bba8dfa91d HIGH 8.8 The surveys plugin for WordPress is vulnerable to generic SQL Injection via the ‘action’ parameter in versions up to… wordfence
444a848d-61bc-4801-815f-d68bea59f5bc HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the Wp Unique Article Header Image plugin 1.0 and earlier … wordfence
442252f8-2896-44ba-a19c-d153b03b268b
< 2.4.8
HIGH 8.8 The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_… wordfence
4403fbe3-965b-4eb9-976f-efbfbf99b2e8
< 2.4
HIGH 8.8 The Slider a SlidersPack plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.… wordfence
43b04825-d1c6-4e2a-9035-1f4fbfe14818
< 1.7.15
HIGH 8.8 The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14… wordfence
43a60896-3b88-4b36-b6d9-46812b8ba35b HIGH 8.8 Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV comma… wordfence
439e4c99-8f34-4e66-9d86-c0cbb8cf6da0
< 4.4.42
HIGH 8.8 The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, … wordfence
437e8d95-2ab3-4cb0-94ca-110f742d6eff
< 2.1
HIGH 8.8 The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language … wordfence
437712f5-a493-4625-a314-856f0d0d9758
< 1.4.2
HIGH 8.8 The Better Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ… wordfence
4372e6a4-3671-4110-bebb-85c1a97c5abb HIGH 8.8 The ipBlockList plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. … wordfence
4336d597-7e87-46eb-8abd-9fafd6cd25d9
< 1.2.90
HIGH 8.8 The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in vers… wordfence
431331aa-4d9f-41f2-a522-567bbd9b8831
< 5.12.1
HIGH 8.8 The Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
430b7e72-72b8-4cf8-99f4-ee1d1d4b4f24
< 1.1.24
HIGH 8.8 The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all ve… wordfence
430a0b93-2cb7-45bf-86ac-4a8b3a0be77a
< 1.2
HIGH 8.8 The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks wi… wordfence
4306b3b2-2834-4445-8c85-afc5c39f4632
< 2.6.4
HIGH 8.8 The Namaste! LMS plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.6.3 via … wordfence
43039f2a-b3f9-4836-8b55-e8a091b1a102 HIGH 8.8 The WP-GeoMeta plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wp_aj… wordfence
4301666c-98a5-4028-978f-f50e5b8f4a6a HIGH 8.8 The FoxyPress plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and includin… wordfence
42f54887-ce98-4360-8d07-37b1a48fc3fd
< 13.2.6
HIGH 8.8 The WP Statistics plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘agent’ parameter in … wordfence
42b373da-d5a6-4e3b-90f4-059da3641841
< 4.5.5
HIGH 8.8 The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5… wordfence
42a4ef37-c842-4925-b06a-3e6423337567
< 2.0.23
HIGH 8.8 The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due t… wordfence
429ce9e6-e51b-4f1e-8e26-f679b08d68d3
< 1.5
HIGH 8.8 The Debug Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
← Prev 182 183 184 185 186 187 188 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top