πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 194 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2ef3c7fb-27f5-4829-8cb6-d3a52778a689
< 5.9.0
HIGH 8.8 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in … wordfence
2ee331d9-32b3-4be4-8f25-d65c1192ff6b HIGH 8.8 The Convert Docx2post plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
2edb574d-74b7-4f72-91a1-bb6632709b7a
< 3.6.5
HIGH 8.8 The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including 3.6.4,… wordfence
2ec6cf42-291b-452d-ad14-80ae1cd5ec5c
< 1.7.1
HIGH 8.8 The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. T… wordfence
2eac991e-fc34-456c-a9a6-d30fde39fd42 HIGH 8.8 The HTML5 MP3 Player with Playlist Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to… wordfence
2ea89c44-8ed0-4ab7-a049-4d1b03a898c7
< 5.00
HIGH 8.8 The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up t… wordfence
2e9142b2-2935-4644-8c56-00789948202b HIGH 8.8 The HQ Rental Software plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
2e840f76-1b46-452e-bd63-507cbab779b9
< 3.2.0
HIGH 8.8 The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capab… wordfence
2e61942e-15ea-468c-b71a-50396d5b2730
< 2.2
HIGH 8.8 An issue was discovered in the read-and-understood plugin 2.1 for WordPress. CSRF exists via wp-admin/options-general.ph… wordfence
2e329432-c404-4312-969b-42cac345637d
< 1.23.3
HIGH 8.8 The UpdraftPlus plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the 'updraft_… wordfence
2e29a67b-2b67-4cd5-a5ae-a931900c75cd
< 1.3.9
HIGH 8.8 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to… wordfence
2e1a68fb-51c6-4567-9a50-78ed44ccac21 HIGH 8.8 The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and … wordfence
2dc616d6-489a-426b-bb52-a0449f907152
< 3.0.0
HIGH 8.8 The Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… wordfence
2da019d3-4aca-485a-aa0c-73728dc1e7c1 HIGH 8.8 The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due t… wordfence
2d7feea5-965f-4a07-90f8-39ccdba7b50f
< 3.5.0
HIGH 8.8 A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (… wordfence
2d7bc556-cdaf-42a7-8801-ad2e4945a137
< 4.0.5
HIGH 8.8 The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inc… wordfence
2d70b9b6-a1f0-4449-8d1a-ae16dbcc844d
< 2.0.2
HIGH 8.8 The Better Font Awesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
2d29f77c-b86d-4058-b528-27631e8a1f2e
< 7.0.8
HIGH 8.8 The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versio… wordfence
2d20e8c9-975d-4e8c-8bea-50935853c7d4
< 2.20.2
HIGH 8.8 The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and… wordfence
2d07880b-9af1-4b1e-aa70-b95ef10a6e33
< 3.6
HIGH 8.8 The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the… wordfence
2ce1a40f-1489-42be-963e-052274a56e47
< 2.0.6
HIGH 8.8 The wpForo Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.… wordfence
2cb275d5-ec4b-419f-84e1-84172d381411
< 3.2.5
HIGH 8.8 The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and… wordfence
2caed42f-fb5b-488a-af15-f5ad3d82a68c
< 2.4.1
HIGH 8.8 The Profile Builder plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.4.0. … wordfence
2c994021-d429-4652-ada5-34ec0517cb19
< 2.3
HIGH 8.8 The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL stateme… wordfence
2c69dec6-4988-4760-8dc0-a11044dde406 HIGH 8.8 The WP User Profiles plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.… wordfence
← Prev 191 192 193 194 195 196 197 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top