πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 199 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
23b5cc65-70d2-46b1-a37a-97af231aff51
< 1.2.5
HIGH 8.8 The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment. wordfence
23a73680-ed13-4250-95e8-2933403f54e6 HIGH 8.8 The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Priv… wordfence
23a20e57-0228-4e37-a105-e693c05a0a24
< 1.6.0
HIGH 8.8 The Creative Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5… wordfence
23a1128f-b8a1-4dec-adf4-43fb96806b60
< 2.9.3
HIGH 8.8 The Yogi - Health Beauty & Yoga WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all version… wordfence
235b197f-030e-4da2-8edf-e263fab6df14
< 0.3.2
HIGH 8.8 The ExS Widgets plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.3.1. … wordfence
2331a587-b731-43d9-b813-9f08efc60bfc
< 5.5.21
HIGH 8.8 The GetResponse plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.5.1… wordfence
232f3a15-3bd3-44fa-aa07-f055e8fcda88
< 1.7.8
HIGH 8.8 The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in a… wordfence
232a274f-c194-4c5b-a1a8-899a822e47fc
< 4.7.6
HIGH 8.8 The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import cla… wordfence
2318b3e1-268d-45fa-83bf-c6e88f1b9013
< 4.6.0.1
HIGH 8.8 The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and includi… wordfence
22fa8290-ebab-4fa4-bcba-0053c3b79f76 HIGH 8.8 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Reques… wordfence
22f79a03-9195-4d5d-a189-9b5e1d3307c8
< 1.2.5.4
HIGH 8.8 The Contact Form 7 Database Addon plugin for WordPress is vulnerable to SQL Injection in versions up to, and including 1… wordfence
22d5a45b-41bd-4f65-b8b7-d7efb2b9cecf HIGH 8.8 The External featured image from bing plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,… wordfence
22d58028-a12c-4d72-b275-ba37a58dc10d HIGH 8.8 The Dashicons + Custom Post Types plugin for WordPress is vulnerable to authorization bypass due to a missing capability… wordfence
22b63369-c6ea-42e9-bea3-d15837da7732
< 1.2.6
HIGH 8.8 The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path… wordfence
229c146d-3f99-4f63-9a6f-997075846815 HIGH 8.8 The Postem Ipsum plugin for WordPress is vulnerable to unauthorized modification of data to Privilege Escalation due to … wordfence
229235de-03c6-4560-b0ea-ab21fde256be HIGH 8.8 The HTML5 SoundCloud Player with Playlist Free plugin for WordPress is vulnerable to PHP Object Injection in all version… wordfence
228147c2-97c6-4910-b9b2-d6ca62fc1760
< 3.2.49
HIGH 8.8 The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
22755d65-d187-438a-9a3f-e7d38497282b
< 4.1.2
HIGH 8.8 The MainWP Maintenance Extension for WordPress are vulnerable to SQL Injection via an unknown parameter due to insuffici… wordfence
22713937-d834-46cf-83ec-6f9f61b548e3
< 1.6
HIGH 8.8 The Conditional Marketing Mailer for WooCommerce Plugin for WordPress is vulnerable to Cross-Site Request Forgery in ver… wordfence
225ea5b3-08a9-40c2-a755-7783475946c4 HIGH 8.8 The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
225123aa-1ef9-4431-b4b1-b5ac5e034ef4 HIGH 8.8 The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX… wordfence
2238c9ba-6d00-4a21-a050-7b8a5f307964
< 1.0.14
HIGH 8.8 The WordPress Facebook plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in versi… wordfence
222db62c-8ffc-4b79-8f04-101caf82186d
< 1.3.0
HIGH 8.8 The case-addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … wordfence
2224b17e-e327-4b86-85db-ad878f989839
< 1.5
HIGH 8.8 The QAEngine theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.4 via the 'cl… wordfence
220055ff-683c-47a4-8817-b3e70bb9dc81
< 1.3.3
HIGH 8.8 The Adapta RGPD plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2… wordfence
← Prev 196 197 198 199 200 201 202 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top