🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 195 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2c643074-d57e-4878-b61d-2790ce9dadaa HIGH 8.8 The OAuth Client by DigitialPixies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
2c358cbe-7600-43a1-94a3-1530cdb5a9f3
< 4.2.9
HIGH 8.8 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP… wordfence
2c25a344-4876-4ba8-bbc6-d1a32f4b1d08
< 1.7.1
HIGH 8.8 The User Login History for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and … wordfence
2c056904-5b2d-4ca6-8dcf-8ab5c1a7645b
< 2.5.2
HIGH 8.8 The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plug… wordfence
2bdb68bc-b773-4537-98dd-c54ffa5309c7
< 1.16
HIGH 8.8 The ImageInject plugin 1.15 for WordPress has CSRF via wp-admin/options-general.php. wordfence
2bd2ce54-9ccb-4943-a01a-c9e8c1ff2d0d
< 3.1.9.2
HIGH 8.8 The WordPress Countdown Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
2bb4ead4-b2ad-42b4-92a0-fb7293f6df06
< 6.30.16
HIGH 8.8 The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, … wordfence
2b881c73-2dfc-4b73-99f3-33432b750efd
< 2.5.6
HIGH 8.8 The Page View Count plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
2b84804d-cb60-4f83-a027-60455c9556c3 HIGH 8.8 The Solar Energy theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5 via des… wordfence
2b8306b8-1f4c-48fb-8eb7-bf02a2f77e04
< 1.62
HIGH 8.8 SQL injection vulnerability in wp-postratings.php in the WP-PostRatings plugin 1.50, 1.61, and probably other versions b… wordfence
2b5d27cc-c6eb-4c5c-8ee1-30483b91c6fd
< 4.3.2
HIGH 8.8 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP… wordfence
2b4df2b3-8d85-4e5c-8ead-92ed2259c84a HIGH 8.8 In the Orange Form WordPress plugin through 1.0.1, the process_bulk_action() function in "admin/orange-form-email.php" p… wordfence
2b39abc8-9281-4d58-a9ec-877c5bae805a
< 2.4
HIGH 8.8 The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
2b38f102-e3ad-4715-99d0-ef8524e5c455 HIGH 8.8 The Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation plugin for WordPress is vulnerable to arbitr… wordfence
2b23b71d-1231-44ce-b992-5e74ddafb4bd
< 1.1.6
HIGH 8.8 The bbPress Move Topics plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1… wordfence
2ae70225-3597-463b-907c-d2a3a7bcecb4
< 1.0.8
HIGH 8.8 The WooCommerce Stock Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability che… wordfence
2ae0d83b-a444-4141-89da-b63ce216db17
< 4.0
HIGH 8.8 The Ajax Search Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… wordfence
2acd40d5-8a9c-4ca8-9c89-5bf639b1c66c
< 1.3
HIGH 8.8 The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
2a691f92-9eff-4777-8198-b7cc5d9e73c0
< 1.7.8.5
HIGH 8.8 The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin… wordfence
2a681cef-649f-4342-beb6-914674bbf6d6
< 0.1.0.9
HIGH 8.8 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in al… wordfence
2a64b1ff-0d3f-42fa-bab2-4f31bb8f0476
< 2.2.1
HIGH 8.8 The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via many parameters in versions up to, and including, … wordfence
2a4e8dbe-9889-43b1-8e15-e96791b13093
< 5.9
HIGH 8.8 Cross-Site Request Forgery (CSRF) vulnerability in KubiQ CPT base plugin <= 5.8 at WordPress allows an attacker to delet… wordfence
2a49db7f-62fc-472d-9edf-de5edbe48219
< 9.6
HIGH 8.8 The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via the… wordfence
2a296dd3-fbcb-4443-a905-9cbaa87faf7d
< 1.4.7
HIGH 8.8 The one-click-ssl plugin before 1.4.7 for WordPress has CSRF. wordfence
2a1ee053-18bc-4fcd-8bb9-d5295c503d20 HIGH 8.8 The WooCommerce Registration Fields Plugin - Custom Signup Fields plugin for WordPress is vulnerable to Privilege Escala… wordfence
← Prev 192 193 194 195 196 197 198 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top