πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 187 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3fda31fa-efc9-44b9-99ba-9e3e23aa2ee0
< 1.9.3
HIGH 8.8 The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_op… wordfence
3f9bf252-dcfb-4142-8301-1a5b565e975a
< 0.3.3
HIGH 8.8 The FunCaptcha – Anti-Spam CAPTCHA plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before… wordfence
3f92c416-8e95-4097-9f16-e1f9389b2334 HIGH 8.8 The Builderall for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and incl… wordfence
3f6b435b-d8b4-434b-8cac-cc3adbc437eb
< 4.7.35
HIGH 8.8 WordPress Core is vulnerable to Remote Code Execution in multiple release branches, including versions 4.7.0 through 7.0… wordfence
3f630773-f65a-44a5-9b84-ea542c78a69a
< 1.10.4
HIGH 8.8 The Clean Login for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.3. This… wordfence
3f5fa5c1-311a-4e35-83c8-387f8039e671 HIGH 8.8 The Essential Breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
3f074584-ec8a-4259-b959-fe37c0244acc HIGH 8.8 The Wishlist Member plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
3f061e7f-6a87-4d4a-9b4e-8234883f2ebc
< 3.17.0
HIGH 8.8 The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalatio… wordfence
3edfc4af-2a28-4bdf-becf-018d9f656947
< 1.7.1050
HIGH 8.8 The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and in… wordfence
3ebe25a7-fa4d-4e3f-b969-2ff3a8388b06
< 0.8.5.8
HIGH 8.8 The WP Fastest Cache plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.8.5.… wordfence
3ebc324a-4858-4502-b962-a4e26ca7445e HIGH 8.8 The Make A Statement theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
3e91fabe-469f-4743-bb8d-76ef20313b37
< 5.99
HIGH 8.8 Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authen… wordfence
3e900c98-5ab1-4674-b820-553c44df7c02 HIGH 8.8 The FavIcon Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
3e8a25d1-4bd8-4ecf-ac10-a333abaac328
< 3.2.6
HIGH 8.8 The Image Intense plugin for WordPress is vulnerable to unspecified SQL Injection in versions up to, and including, 3.2.… wordfence
3e03bc79-b42e-4015-8476-2b0488c71028
< 4.5.3
HIGH 8.8 An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authent… wordfence
3e037931-870f-45eb-973c-0276911682ad
< 1.4.0
HIGH 8.8 The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up… wordfence
3de5ebda-a935-46fb-b35f-2f3784a63203
< 6.5.1
HIGH 8.8 The PDF Invoices for WooCommerce + Drag and Drop Template Builder plugin for WordPress is vulnerable to PHP Object Injec… wordfence
3dc7bc0a-b209-431f-a9f1-f850b1a1d1b4
< 3.5.0
HIGH 8.8 The GiveWP plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.2 via de… wordfence
3dbe01a5-a6ab-42d6-a485-ec54a4a62a0f
< 5.0
HIGH 8.8 The Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript plugin for WordPress is vulnerable … wordfence
3d96d38a-7f0e-4e47-ba49-727705eaaac6 HIGH 8.8 The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 vi… wordfence
3d933256-765b-4e1b-b5a1-39bf767bf860 HIGH 8.8 The Mojoomla School Management System plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in unkn… wordfence
3d6629e9-ab43-4eca-9340-5691421ab19d
< 1.7.11
HIGH 8.8 The Contact Form by Supsystic plugin for WordPress is vulnerable to generic SQL Injection via the 'sidx' and 'sord' para… wordfence
3d5c5511-570e-4048-8c1b-68cfc831f0c6
< 3.0
HIGH 8.8 The Advanced Menu Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
3d56fdde-ab7a-4e7c-9f48-48e71e09a681
< 5.6.12
HIGH 8.8 The OWM Weather plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.1… wordfence
3d36d52e-7247-4f06-ae10-7827ae242983
< 1.9
HIGH 8.8 The AdsforWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8. Thi… wordfence
← Prev 184 185 186 187 188 189 190 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top