πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 196 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2a0f9f80-e338-4afd-9a4b-e421865c8b0b
< 1.5.29
HIGH 8.8 The Page Builder: Live Composer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and in… wordfence
29e76d57-217f-4f21-8bc6-a86290783a19
< 3.1.9.7
HIGH 8.8 The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and … wordfence
29e49f76-9769-41c9-aeed-9e2857ebbd25
< 1.7.11
HIGH 8.8 The Coming Soon by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
29da4c49-3608-4bff-8184-01dc08752403
< 1.1.0
HIGH 8.8 The Fatcat Apps Analytics Cat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
29d72347-ba49-45c6-a964-2c75064ac866
< 2.4
HIGH 8.8 The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path … wordfence
29c0fb4d-c38c-4c78-9e15-797f3c3a4b30
< 2.7.2
HIGH 8.8 The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creat… wordfence
2984b9ca-e821-4c23-b792-4d0e54e44a7c
< 5.11.1
HIGH 8.8 The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cr… wordfence
297c7411-5065-458c-8cad-4f6243610b8a
< 6.2.10
HIGH 8.8 The Advanced Custom Fields Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… wordfence
29778d95-4859-4383-91c7-15e7907b825c
< 3.7.28
HIGH 8.8 In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted meta… wordfence
296f8a23-8223-4d9c-a238-d93fcd5abd87
< 2.3.4
HIGH 8.8 The EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) plugin for … wordfence
2954583e-4ebe-4658-b132-0085f2b1cf08
< 1.0.15
HIGH 8.8 The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability che… wordfence
293ac389-cc82-400c-ab50-8e53f00c925a
< 6.3
HIGH 8.8 The Display Eventbrite Events plugin for WordPress is vulnerable to Local File Inclusion via the 'layout' attribute in a… wordfence
29169235-03d3-43a7-9afd-ddfc1a486faf
< 1.6.7
HIGH 8.8 The Subaccounts for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all v… wordfence
29143d81-9134-4b0e-8540-5f37e5b08707
< 5.3
HIGH 8.8 The Crossword Compiler Puzzles plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… wordfence
28e74811-aae8-4276-abb1-cbe4fbcfd08b HIGH 8.8 A vulnerability was found in Global Content Blocks Plugin 2.1.5. It has been declared as problematic. This vulnerability… wordfence
28e1a11b-5320-41be-bc78-580322e5f407
< 2.10.16
HIGH 8.8 An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did … wordfence
28d3388e-0731-46b6-bf66-e7a1d98c321a
< 5.9
HIGH 8.8 Multiple SQL injection vulnerabilities in cs_admin_users.php in the wp-championship plugin 5.8 for WordPress allow remot… wordfence
28c3b377-4cab-4c17-adc3-6ce8b600b20a HIGH 8.8 The Woo MerchantX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0… wordfence
289c9759-f4d3-4b42-9f90-12ea43bbafad
< 4.1.14
HIGH 8.8 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
284b9b04-aa8f-41ff-b944-3488c5da8e20
< 2.0.9
HIGH 8.8 The Listing, Classified Ads & Business Directory – uListing plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
283c2b7b-b231-4a23-96be-776115676443
< 2.6.5
HIGH 8.8 The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option. wordfence
28333161-9c76-4108-9256-9ffa91eaf818
< 4.6.4
HIGH 8.8 The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms. wordfence
281c336e-7a1e-4106-ae79-b3b512b430ca
< 1.9.9.5.2
HIGH 8.8 The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… wordfence
2812b31d-11c0-4efe-95e2-ea713293dad1
< 6.3.1
HIGH 8.8 Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Post… wordfence
27e40af7-5697-4482-a96d-9216886c363b
< 2.7.27
HIGH 8.8 The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 … wordfence
← Prev 193 194 195 196 197 198 199 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top