πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 190 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
38a079c8-181c-4bd8-a45d-e132711029ff
< 4.0.2
HIGH 8.8 The Enable Media Replace plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, … wordfence
3889d01d-a961-46b9-a86e-8ab19641cf2d HIGH 8.8 The Doctor Appointment Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includi… wordfence
3871bae4-f954-4692-8af8-1f96f8fcb778
< 4.0.9
HIGH 8.8 The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missi… wordfence
3856289b-6e82-4d05-afa2-ea561a4e5c30 HIGH 8.8 The GERRYWORKS Post by Mail plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ… wordfence
37f7f9ef-d57a-41e9-bd2c-2aa04a82b6c4
< 2.0.6
HIGH 8.8 Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers… wordfence
37f704bf-82bc-44f7-8b3c-cbf117732aaf HIGH 8.8 The Dailydeal by Templatic theme for WordPress is vulnerable to arbitrary file uploads via CSRF due to missing or incorr… wordfence
37d4d038-3f5c-4c4a-b5f1-3dd23a5b345e
< 4.0.26
HIGH 8.8 The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.25 via the … wordfence
37a25fdf-da5d-42bd-a803-afb3787aabf4
< 1.5.2
HIGH 8.8 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Ma… wordfence
376f2fbf-98a4-49d9-bd22-40da5d37b62d
< 2.6.0
HIGH 8.8 The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upl… wordfence
3762cd92-604a-4dac-a09e-6b4a08c4d804
< 0.5.16
HIGH 8.8 The Duplicator plugin for WordPress is vulnerable to SQL Injection in versions up to and including 0.5.14 due to insuffi… wordfence
373e9a7c-cdc3-43cb-9c8f-2be25f514b61
< 2.8.3
HIGH 8.8 The Visual Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
372a4550-c38e-46d6-b7f2-15e05708d128
< 0.9.5
HIGH 8.8 The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 0.9.5. This is … wordfence
370a6130-425c-4264-baaf-8989d3b00d14
< 4.8.5
HIGH 8.8 The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
37052cb9-8479-4004-9161-65f37028ae10
< 4.1.5
HIGH 8.8 The Bit File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
3702218f-a5ad-4244-874f-53b49cc9491c
< 2.2.7
HIGH 8.8 The Social Share Buttons by Supsystic plugin for WordPress is vulnerable to SQL Injection via several unknown parameters… wordfence
36e83a33-63e7-4282-9b3c-282bd21830b7
< 3.6.1.1
HIGH 8.8 The JetFormBuilder β€” Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all ver… wordfence
36e15052-0e04-4b72-b573-b736109517b8
< 3.7.35
HIGH 8.8 wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to… wordfence
36d02d5f-d534-4567-9587-1f6e4b21ca90 HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the DVS Custom Notification plugin 1.0.1 and earlier for W… wordfence
36ad7fe2-0dc9-427d-811b-8fb1fdb78579
< 1.3.1
HIGH 8.8 The ARI Stream Quiz – WordPress Quizzes Builder plugin for WordPress is vulnerable to PHP Object Injection in all vers… wordfence
36abba4d-9a73-4ef2-a910-6030acddd182 HIGH 8.8 The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the u… wordfence
368cff00-6a86-443e-aec4-4115a229a3c1
< 2.0.9
HIGH 8.8 The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up … wordfence
3624708c-b0da-4177-a8e8-cf5f5c432f97
< 2.11.8
HIGH 8.8 The WP Debugging plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.11… wordfence
361e2d5c-4355-4e71-91aa-2c1bc6b6fb78
< 21.3
HIGH 8.8 The "Frontend File Manager Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
3608fce3-0869-4516-ae08-68108f733c37
< 5.0.30
HIGH 8.8 The WordPress Menu Plugin β€” Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
3604aece-5e76-4e8e-9caf-f518d6001277
< 1.93.1 (02-07-2025)
HIGH 8.8 The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up… wordfence
← Prev 187 188 189 190 191 192 193 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top