🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 189 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3b1b60f4-39f7-4981-bd8d-b1c6e63cf082
< 4.24
HIGH 8.8 The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to u… wordfence
3aecc02a-fd49-4743-9d7b-894cf657cbc1
< 2.2.0
HIGH 8.8 The Asgaros Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1… wordfence
3acbdb2a-e7c6-4062-b48a-7035e464edaf
< 5.6.5
HIGH 8.8 The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
3ac48cd9-1de5-4840-b3f3-dc24ca52442e
< 2.6.85
HIGH 8.8 The Smart Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
3abac0a1-a696-48b1-88d9-d0b102c82ac3
< 1.1.1
HIGH 8.8 The WHIZZ plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.1.1. This is due to missi… wordfence
3ab6ed55-7067-4318-865b-33dcfc584386
< 4.0.2
HIGH 8.8 The GSheetConnector For WPForms – WPForms Google Sheets Integration (Real-Time Sync) plugin for WordPress is vulnerabl… wordfence
3aa537bc-90fa-4d87-9dd5-e32aef4273c7
< 1.1.0
HIGH 8.8 The Cart Link for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
3a9f7a61-535f-45c8-a7e7-e8b095cacaa1
< 1.5.63
HIGH 8.8 The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php. wordfence
3a6316d8-1d64-4d28-b28a-00ca0b5facee HIGH 8.8 The Read more By Adam plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
3a58644a-c678-41e7-8020-d2f2c247682f HIGH 8.8 The G-Lock Double Opt-in Manager plugin for WordPress is vulnerable to generic SQL Injection via the 'json' parameter in… wordfence
3a2c62a8-bc00-43b7-a3e8-a45d0cb75854
< 5.0.0
HIGH 8.8 WordPress plugin wp-cleanfix has Remote Code Execution wordfence
3a17b6ad-c778-4677-b5bd-6ffc9b425ba1
< 4.4.4
HIGH 8.8 The Quiz And Survey Master plugin for WordPress is vulnerable to Multiple SQL Injections via several parameters in versi… wordfence
3a17560b-4fe0-4e1b-b4a2-c411f1123914
< 3.3.6
HIGH 8.8 Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sit… wordfence
3a12945d-a67c-4a19-a4e7-f65f5f2a21bb
< 13.2
HIGH 8.8 The Superb slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions … wordfence
39f12569-ff89-4c6b-afcf-a8c4421749cc
< 3.1.37.12.L
HIGH 8.8 Vulnerability in wordpress plugin Event Expresso Free v3.1.37.11.L, The function edit_event_category does not sanitize u… wordfence
398ebe7e-b0a7-47d8-b2f2-61973182f520 HIGH 8.8 The FoxyPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.4.9. … wordfence
396f785f-0354-462e-bcaa-69e364c8c4b5 HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the TweetScribe plugin 1.1 and earlier for WordPress allows remote at… wordfence
396ecd5b-d351-4289-aea4-332af5101f10
< 2.0.3
HIGH 8.8 The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in… wordfence
391ed7a2-64db-4a79-a697-86c70c60d02e
< 0.8.7
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to hi… wordfence
391e12f7-9521-4ac6-bd78-ac28df72030b HIGH 8.8 The BNG Gateway For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
390ee957-f06f-4952-b740-4578c130925f
< 1.4.5
HIGH 8.8 The WP Email Users plugin for WordPress is vulnerable to SQL Injection via the ‘filetitle’ parameter in versions up… wordfence
390a541e-68dd-43dd-8fe4-5334c534552c HIGH 8.8 The Betheme theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 28.4.2. Thi… wordfence
38ea001c-6edb-4f36-a7ec-19be1d857b9e
< 3.2.5
HIGH 8.8 The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all v… wordfence
38c6b149-39d7-491a-9f3a-261087a52a03 HIGH 8.8 The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to… wordfence
38bf21c4-bf2e-4096-b4e3-9e3a5a60f1ad
< 3.2.1
HIGH 8.8 The Companion Auto Update plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
← Prev 186 187 188 189 190 191 192 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top