πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 192 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
341cbd60-33b9-49f8-b8f3-3c44664ce463 HIGH 8.8 The Hover Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1… wordfence
34110479-2581-4710-82ff-1d53535d83e1
< 4.2.0
HIGH 8.8 The LearnPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.1.7.3.2 due to in… wordfence
340d6e92-81a0-4659-b60b-922f63476a33
< 1.47
HIGH 8.8 The SrbTransLatin plugin 1.46 for WordPress has CSRF via an srbtranslatoptions action to wp-admin/options-general.php. wordfence
33f07db9-ff4f-4f81-bf32-18b04d19624d
< 2.6.6
HIGH 8.8 The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.6.6. This m… wordfence
33aed550-5a2d-4a0a-8199-f2dfd212be92 HIGH 8.8 The Mega Addons For WPBakery Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
338a4238-900c-4f3e-a724-52c4b3603af2
< 2.9.3
HIGH 8.8 The Yogi theme for WordPress is vulnerable to PHP Object Injection in versions up to, and excluding, 2.9.3 via deseriali… wordfence
3368e4b4-9876-447b-acb4-3648e83ed997
< 4.0.5
HIGH 8.8 The Acunetix WP Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
33517dba-78ac-4391-a55e-d1f13801b212
< 3.7.7
HIGH 8.8 The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of dat… wordfence
332f8a7e-2342-4b77-a7d6-17137e432b5b
< 1.2.1
HIGH 8.8 The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which cou… wordfence
33129b72-0976-4c09-9cea-b5ba321ae46f
< 3.3.7
HIGH 8.8 The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via… wordfence
33086968-359f-46d7-825e-29c4e4449899
< 2.12
HIGH 8.8 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time … wordfence
32d80824-c420-40e8-8c07-fb17b1b50644
< 1.3
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the FourSquare Checkins plugin before 1.3 for WordPress allows remote… wordfence
32b6938a-0566-46c8-8761-0403b3a0e3e9
< 4.6.19
HIGH 8.8 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to blind SQL Injection via the rtme… wordfence
32b3ad84-6adb-44c1-942a-51f27638c8c9
< 1.3.7
HIGH 8.8 The Multiple Roles plugin for WordPress is vulnerable to privilege escalation in versions before 1.3.7. This could allow… wordfence
329f6e9b-f2f4-4c4e-9512-fcf504c2c0ed
< 1.3.3
HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Sticky Footer plugin before 1.3.3 for WordPress… wordfence
327f645b-4990-4b5e-b39c-6c55ac4e66f0
< 2.7.1
HIGH 8.8 The WP Easy Gallery for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7. Thi… wordfence
327f5628-20f8-4e37-9c54-d37d61e939b3
< 1.4.5
HIGH 8.8 The EmpikPlace for Woocommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includi… wordfence
327e706d-2d6c-4204-a531-281f2e2dbcf0
< 2.5
HIGH 8.8 The Horizontal scrolling announcements plugin for WordPress is vulnerable to SQL Injection via the plugin's 'hsas-shortc… wordfence
327a155c-7a7d-494d-94d1-f7e7ee8927f0
< 2.0.6
HIGH 8.8 The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl… wordfence
32725074-5c62-49e0-83f9-c6cb77fb77a4
< 2025.03.27
HIGH 8.8 The Administrator Z plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e… wordfence
32419c04-bd10-431a-b87c-1975dacc2e01 HIGH 8.8 The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, wh… wordfence
320c0c1d-9d1b-43d7-aca5-2104b2a63e8f
< 2.6.6
HIGH 8.8 The Kraken.io Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
31de3c9b-068d-47d8-9811-feae07f2e9d0
< 3.6.6
HIGH 8.8 The WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post … wordfence
31c10c95-fe6a-4e2d-a472-b6e8b8bc7fe7 HIGH 8.8 The Insertify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. … wordfence
31b67763-0542-4c50-9713-434d15c18cb7 HIGH 8.8 The Bstone Demo Importer plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on… wordfence
← Prev 189 190 191 192 193 194 195 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top