πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 198 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2547ec16-76c8-4cc2-b10b-d321324d9363 HIGH 8.8 The Celestial Aura theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in al… wordfence
250202d5-3a0d-494c-8386-1f4cd015ad7e
< 9.2.0
HIGH 8.8 The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es… wordfence
24f23230-7012-48c0-85e7-71518340cf95
< 1.3.1
HIGH 8.8 The Consulting Elementor Widgets plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i… wordfence
24e00c0d-08ff-4c68-a1dd-77b513545efd
< 5.3.15
HIGH 8.8 The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
24b4eace-7672-4dae-9c0c-bbd1d79765a9
< 2.2.3
HIGH 8.8 The WPAdverts plugin for WordPress is vulnerable to Local File Inclusion via several render() functions in versions up t… wordfence
24aa005f-30c2-4708-bbbe-8eece2cd19cc
< 24.0.1
HIGH 8.8 The WPSolr plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 24.0. This… wordfence
249ccc77-0daf-41bc-b5c5-991bf17d645d
< 2.10.18
HIGH 8.8 The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and in… wordfence
249ac834-e7de-42cc-9ac1-82e7c18eac31
< 3.2.8.1
HIGH 8.8 The wp-members plugin before 3.2.8.1 for WordPress has CSRF. wordfence
24889552-0db6-44e6-9b12-f31b5e92a42e HIGH 8.8 The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modificat… wordfence
2483875a-84de-4a40-a69e-aee68da1ce3b HIGH 8.8 The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and … wordfence
2471d06b-7d9a-41b9-b38c-3f40322d8a5b
< 1.5.4
HIGH 8.8 The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include … wordfence
24697253-62b9-45ff-8427-ee437e0d271f
< 2.9.4
HIGH 8.8 The Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More plugin for WordPress is v… wordfence
24666f75-9179-4043-841b-4dd83be078e8
< 5.0.3
HIGH 8.8 The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This i… wordfence
2460e7c4-76dc-4bc3-bc06-b52df64f5353 HIGH 8.8 The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5… wordfence
245fade9-ecbb-4d41-ae2a-07331f6c25ba HIGH 8.8 The Service plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.4 due to insuffici… wordfence
245f8eec-d496-4298-800d-ea1120640e2d
< 2.5
HIGH 8.8 The Captchinoo, admin login page protection with Google recaptcha plugin for WordPress is vulnerable to Cross-Site Reque… wordfence
245e43e0-3391-486d-9ecf-3e745bceaa1f
< 2.5
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote atta… wordfence
244f087a-ddc6-4f48-812d-3fed9e1536a0
< 3.3.2.1
HIGH 8.8 The Mixed Media Gallery Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and in… wordfence
241d7a82-5fa5-40e3-9336-823644ca17f0
< 2.8.6
HIGH 8.8 The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
24123a4f-da33-4d50-9e82-18f910de6619
< 1.1.8
HIGH 8.8 The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php a… wordfence
241073e4-b8f2-4dd3-ad66-6dda8c61b42c
< 4.0
HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for Wo… wordfence
23f0315f-5523-4e16-8adf-f9fe9254032a
< 6.2
HIGH 8.8 The Super Store Finder, Super Interactive Maps, and Super Logo Showcase plugins for WordPress are vulnerable to arbitrar… wordfence
23d8c56b-01f1-48b4-a58d-958457be738f
< 1.1.4
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the SEO Plugin LiveOptim plugin before 1.1.4-free for WordPress allow… wordfence
23bfcdd1-b99d-47eb-9f88-96f9ecc53b32
< 5.7.20
HIGH 8.8 The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification… wordfence
23b6e418-5560-4543-9042-5f338df315e5
< 2.1.13
HIGH 8.8 The ShopBuilder – Elementor WooCommerce Builder Addons plugin for WordPress is vulnerable to Local File Inclusion in a… wordfence
← Prev 195 196 197 198 199 200 201 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top