ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 191 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
35f91088-3c52-4b32-abe8-94731d631f25
< 1.3
HIGH 8.8 The Custom Fields Account Registration For Woocommerce plugin for WordPress is vulnerable to Privilege Escalation in all… wordfence
35e220c0-1e4d-4365-a1be-de66930fa559
< 5.11
HIGH 8.8 The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cr… wordfence
35dadb9c-f0c6-4b74-bb31-5e9d504b3db5
< 2.8.22
HIGH 8.8 The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via multiple parameters in the 'get_logs' fun… wordfence
35d80441-6cbe-4bd4-a891-a4a1d24c77ec
< 1.3.0
HIGH 8.8 The Easy Media Gallery Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
35afef52-350c-4b61-b9c0-3ae2572f81fb
< 2.9.3
HIGH 8.8 The Folders plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hand… wordfence
3590277a-3319-4707-b728-d75ea59e8ad9
< 3.0.2
HIGH 8.8 The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1… wordfence
358c0068-efd5-4bc8-9853-22fefdd9d76b HIGH 8.8 The Portfolleo plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… wordfence
357257df-123d-4885-ad48-ff38ce29eeb3
< 2.8.7
HIGH 8.8 The Smooth Slider plugin through 2.8.6 for WordPress has SQL Injection via smooth-slider.php (trid parameter). wordfence
3566d9fa-faeb-4302-96e2-464a68eff66d
< 2.7
HIGH 8.8 The Smooth Slider plugin before 2.7 for WordPress has SQL Injection via the wp-admin/admin.php?page=smooth-slider-admin … wordfence
3566b602-c991-488f-9de2-57236c4735b5
< 1.8.1
HIGH 8.8 The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin'… wordfence
3566292a-91c8-4cb9-a1d3-45669d69bfc3 HIGH 8.8 The Q and A plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.6.2. T… wordfence
353c3cd9-5ada-466b-b8e5-d40e0ec4e867
< 3.24.2
HIGH 8.8 The Thrive Theme Builder theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions prior to 3.24.2… wordfence
3538f5df-fd70-454d-87b0-08028dcbe449 HIGH 8.8 The Banner System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.0… wordfence
3513ec24-0b1b-4528-9f89-eee5654e4e98
< 3.3.44
HIGH 8.8 The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
3503c7bf-5e96-4033-89c1-b7c13c5489d2 HIGH 8.8 The WPlite WordPress plugin through 1.3.1 does not have CSRF check in place when updating its settings, which could allo… wordfence
34e31a0f-27de-4536-9a7e-b8f68e557b3f HIGH 8.8 The Quick Post Duplicator for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to… wordfence
34da0e53-70d0-49ea-be7c-c2f610467172 HIGH 8.8 The MDJM Event Management plugin for WordPress is vulnerable to privilege escalation via account takeover in all version… wordfence
34d8ecee-ad52-47cd-ac78-4a82aa2ff58a
< 1.5.4
HIGH 8.8 SQL injection vulnerability in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remote … wordfence
349d960b-cc62-47c6-b0d5-a199e1e679db
< 1.8.2.1
HIGH 8.8 The Frisbii Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.8.2. … wordfence
349cada2-8154-4429-a47a-1837581da1dc
< 3.2.8
HIGH 8.8 The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found … wordfence
3469ba0d-8ef3-41d0-becb-cf2eb43758f1
< 1.0.7
HIGH 8.8 The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_pa… wordfence
344b2f80-ea86-4bf0-8ee4-4b5c7b94c34b
< 1.3.5
HIGH 8.8 The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code exe… wordfence
342b2e81-fb26-416a-8f3d-4bc221260228
< 1.14.6.1
HIGH 8.8 The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization. wordfence
342a4482-f5d3-4cc9-a998-e3abac7142cf
< 4.0.1
HIGH 8.8 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
342049e5-834e-4867-8174-01ca7bb0caa2
< 5.9.14
HIGH 8.8 The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and… wordfence
← Prev 188 189 190 191 192 193 194 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top