ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 188 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3d2236cd-dfed-42d0-a77f-4573e74a4781
< 0.0.9
HIGH 8.8 The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings,… wordfence
3d0a709e-1514-43dd-8719-e9bdfdc610d2 HIGH 8.8 The NMI Gateway For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
3d015c7d-bace-4d00-8ba5-1c85acb08d57
< 1.1.1
HIGH 8.8 The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation. wordfence
3cfec2b8-1df0-4f3f-b6cc-ed0adecaeb16 HIGH 8.8 The Cimy Header Image Rotator WordPress plugin through 6.1.1 does not have CSRF check in place when updating its setting… wordfence
3ce0fece-a7e5-4d27-a70a-37ab0973c15f
< 3.3.1
HIGH 8.8 The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all… wordfence
3cc4a11a-7562-44e7-ac8e-770c4e39e2c7
< 3.5.2
HIGH 8.8 The Academy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
3c8ba503-db7e-4ac1-898f-a301854db60f
< 1.5.5
HIGH 8.8 The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. pl… wordfence
3c833223-c8c9-413f-9d72-6fb13101459b
< 2.4.14
HIGH 8.8 The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13… wordfence
3c730a69-015a-4b36-aa16-eff6916a302f
< 1.2.4
HIGH 8.8 The Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation in versions up to, and… wordfence
3c192623-eb46-4f1d-b897-433ac80608cb
< 1.5.0
HIGH 8.8 The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable t… wordfence
3c021686-3c9d-4382-be5c-9d4bf989cdcd
< 1.6.9
HIGH 8.8 Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remot… wordfence
3bf59f44-356c-4d84-add3-72e8905a80f9
< 1.0.9
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the … wordfence
3bee82d8-d019-450b-b532-5b3e2e3aff6f
< 1.7.0
HIGH 8.8 The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF. wordfence
3bed2531-1a7d-49d9-91c9-d9e7357e5613
< 3.5
HIGH 8.8 The Erident Custom Login & Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
3be36cd6-27a3-4b15-9e43-b1f6c25efae6
< 12.0.8
HIGH 8.8 The wp-statistics plugin before 12.0.8 for WordPress has SQL injection. wordfence
3bdb73f9-d091-4de7-975c-10090ee1f749
< 3.7.4
HIGH 8.8 wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on whi… wordfence
3bc19aca-15df-40c8-a7c4-10ae7faf0308
< 2.0
HIGH 8.8 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Privilege Escalation i… wordfence
3ba8a9f5-0633-4cf0-af27-5466d93e9020
< 3.17
HIGH 8.8 The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter… wordfence
3ba33a18-429f-4a3e-b018-bdfbbe6e8482 HIGH 8.8 The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization… wordfence
3b89319c-53ed-4130-8c67-420a7efef13b HIGH 8.8 The Make Email Customizer for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that c… wordfence
3b7f8739-7f40-40a7-952e-002ea3b82ac7
< 3.1
HIGH 8.8 The Jquery news ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,… wordfence
3b71805c-15bb-4cde-b91f-4f3e9b7ab520
< 2.8.4
HIGH 8.8 The Welcart e-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
3b6c114b-00e0-4d3d-ba8b-dc9b294112db
< 2.2.2
HIGH 8.8 The EKC Tournament Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
3b6ae26e-9262-4241-81d1-d5522bd35345 HIGH 8.8 The Ultimate Product Catalog plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… wordfence
3b345dfe-3945-405a-9825-c88816b2adee
< 3.24.0
HIGH 8.8 The Thrive Themes Builder theme for WordPress is vulnerable to privilege escalation in all versions prior to 3.24.0. Thi… wordfence
← Prev 185 186 187 188 189 190 191 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top