πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 193 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
319e9662-e010-469d-bf04-ee5895077db6
< 2.1.2
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote a… wordfence
3166549e-b52e-41e8-8b5c-1a1a0558c858
< 7.3.0
HIGH 8.8 The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the can_u… wordfence
3144f190-232c-40c0-9e4b-d1cedfe52b26 HIGH 8.8 The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… wordfence
311f3fcd-05b7-43d3-8b2c-aeebee4be3c8 HIGH 8.8 The WPGYM plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 65.0. This makes … wordfence
31093664-c45e-4e87-b72f-5cdf8e8e9f67
< 7.1
HIGH 8.8 The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation … wordfence
30f7a858-6caf-44c3-8fc9-476e9fa86543 HIGH 8.8 The Bitcoin / Altcoin Faucet plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
30bf7a5f-bc1a-4c3b-a49e-79543271e620 HIGH 8.8 The FERMA.ru.net plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.3 due to insu… wordfence
30b9c4ca-1744-4907-930b-28ef5494d29c
< 4.3.3
HIGH 8.8 The wp-database-backup plugin before 4.3.3 for WordPress has CSRF. wordfence
30742fd4-0fdd-4313-afe2-503cbc39c25a
< 1.7.5.3
HIGH 8.8 The MDJM Event Management plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1… wordfence
306f00e4-9a70-48be-a91e-e396643a8129
< 2.3.11
HIGH 8.8 The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u… wordfence
305ffc3b-5f1c-42fb-9fd5-0dfcbe1c661b
< 3.7.21
HIGH 8.8 In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog… wordfence
30529c2b-ef05-4b88-8082-09a633e76736
< 6.9.2.1
HIGH 8.8 The WPJAM Basic plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … wordfence
301f455f-1ffe-485a-8473-8a31a0633a5f HIGH 8.8 The Dimension theme for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce… wordfence
301ad19a-f99c-45c8-83a7-d74e1a260556
< 10.30.33
HIGH 8.8 The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
30079059-be5e-4f1c-a398-b2a0cf5d7669 HIGH 8.8 The Restaurt theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all vers… wordfence
2fe46309-76a7-4f23-996d-0e5dd8e9926a HIGH 8.8 The WeDesignTech Ultimate Booking Addon plugin for WordPress is vulnerable to Authentication Bypass in all versions up t… wordfence
2fd0073c-3f75-4783-838d-d01fdea008c1 HIGH 8.8 The PDF File Browser plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.3 v… wordfence
2fcef7c3-25a5-44e1-96c1-68e67e59f18b
< 2.3.0
HIGH 8.8 The WP Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.9.… wordfence
2fa19840-04a0-4aa8-83c4-d0dca4e72e36
< 1.1.0
HIGH 8.8 The SureDash plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. Thi… wordfence
2f66afc8-8e8f-4802-b2be-a3a706dbf6cb HIGH 8.8 The Hotel Listings plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.… wordfence
2f6669aa-e53c-45bb-88c4-2e1350993423
< 2.7.8
HIGH 8.8 The BuddyForms plugin for WordPress is vulnerable to deserialization of untrusted input via the 'url' parameter in versi… wordfence
2f3a10b5-b024-4b3f-af67-b7fcb997d368
< 2.2.8
HIGH 8.8 The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t… wordfence
2f38498d-0560-4935-b1f5-1fdb62f49a5b
< 1.5.1
HIGH 8.8 The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'do… wordfence
2f060ea1-01e2-4e5b-82ba-b5cdd0d8290a
< 4.6.4.1
HIGH 8.8 The WP Activity Log Premium plugin for WordPress is vulnerable to SQL Injection via the entry->roles parameter in all ve… wordfence
2f025b73-9a1a-4890-90ef-700f73ac018f
< 1.2.5
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote… wordfence
← Prev 190 191 192 193 194 195 196 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top