πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 197 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
27b9ff55-f2b4-4713-a39d-6f57ee4c229b HIGH 8.8 The Simpolio - Fullscreen Portfolio & Blog HTML Theme theme for WordPress is vulnerable to arbitrary option updates due … wordfence
27ac48a7-52ee-46cb-a6d0-efbd2b516445
< 1.3.3
HIGH 8.8 The users-customers-import-export-for-wp-woocommerce plugin (and other Webtoffee plugins) before 1.3.9 for WordPress all… wordfence
279e6990-3423-437b-b484-34e80240218e
< 1.1.8.1
HIGH 8.8 The AI Image Generator for Your Content & Featured Images – AI Postpix plugin for WordPress is vulnerable to arbitrary… wordfence
2730a090-e1ae-4fd5-9873-9a15dfc1efd9
< 4.7.6
HIGH 8.8 The PublishPress Authors plugin for WordPress is vulnerable to Local File Inclusion via the filterAuthorBoxHtml() functi… wordfence
272515e3-18ae-4e7f-8503-722d7964b3c2 HIGH 8.8 The Web Invoice plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.3 due to insuf… wordfence
26abf509-f0a9-4849-9028-d6c42832158f
< 2.3.5
HIGH 8.8 The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu… wordfence
267d2b02-6365-4553-9809-bc3a8b070c7e
< 1.8.4.1
HIGH 8.8 The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as… wordfence
265be0af-66a4-4636-ab81-f8e2c5a1282e
< 2.1.7
HIGH 8.8 The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6… wordfence
2659d22f-3b54-4268-8618-b0c685278f6e
< 0.2.7
HIGH 8.8 The Extra Block Design, Style, CSS for ANY Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site Request For… wordfence
2657aa8a-b2de-4cb4-b9f8-e7fb0c887a7a
< 4.11.3.4
HIGH 8.8 The WooCommerce Affiliate Plugin – Coupon Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
264cb002-bf40-4cc2-9c21-cda9bb24f494
< 6.1
HIGH 8.8 The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi… wordfence
26399541-a6a7-4c01-b72c-1ebf73f18c84
< 1.5.7
HIGH 8.8 The Store Toolkit for WooCommerce plugin for WordPress is vulnerable to missing authorization checks on the woo_st_admin… wordfence
2636efe7-20c4-4d12-ab2f-45035e8a1ca0 HIGH 8.8 The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_s… wordfence
262db9aa-0db5-48cd-a85b-3e6302e88a42 HIGH 8.8 The Google Maps made Simple plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions u… wordfence
260f805a-8022-40f7-a2f4-1bbbf81c1e8b
< 2.0.1
HIGH 8.8 The Corpkit - Business Consulting WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to mis… wordfence
26050f70-7a10-4df5-acd5-1c9e7613bf2c
< 2.5.4
HIGH 8.8 The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to,… wordfence
25fab7b3-59ce-44ca-83fa-bd25b7f31af0 HIGH 8.8 The "Follow Me Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
25f71a19-85b1-4bc9-b193-d9de2eba81ee
< 1.5.91
HIGH 8.8 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code… wordfence
25e9dbfd-a24e-400c-b926-051c1eb3643a HIGH 8.8 The Theme File Duplicator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
25e4abf4-9869-436c-8fd3-9f59b2363ba7 HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the twimp-wp plugin for WordPress allows remote attackers to hijack t… wordfence
25b94c05-87c5-44fb-90d5-6c65d035dba6
< 3.4.34
HIGH 8.8 The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it ha… wordfence
25affa52-13a7-4726-b02a-5af78afa8acf
< 4.0.1
HIGH 8.8 The WP-BusinessDirectory – Business directory plugin for WordPress plugin for WordPress is vulnerable to arbitrary fil… wordfence
25a25dae-578b-40d6-95c3-8428ca545ac3
< 0.9.1
HIGH 8.8 The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via… wordfence
25a05249-d899-429b-a7d3-c283c03a48a2
< 13-07-2019
HIGH 8.8 Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter. wordfence
2577102f-6355-4483-bd3d-1948497cb843
< 4.9.9.3
HIGH 8.8 The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2… wordfence
← Prev 194 195 196 197 198 199 200 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top