🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 200 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
21f8f5be-b513-4040-af39-c1a61d7e313f
< 3.3.13
HIGH 8.8 The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat… wordfence
21be2215-8ce0-438e-94e0-6a350b8cc952
< 5.7.23
HIGH 8.8 The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all … wordfence
21bcb740-6340-4ff7-815f-539175936ca1
< 1.4.0.3
HIGH 8.8 The Cwicly plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.0.2. Th… wordfence
21ab1a1e-53f5-4cd2-a9c5-0b0065f14a6a HIGH 8.8 Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on Wo… wordfence
218b4564-bfaf-4e65-94c4-b6b15b60b707 HIGH 8.8 The Activity Reactions For Buddypress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
211350ac-24c4-4aa7-aea6-5dc44f753185
< 2.5.2
HIGH 8.8 The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backu… wordfence
20f1600e-6404-4f60-b415-e6588e26f97d HIGH 8.8 The SW Contact Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to ins… wordfence
20cd3fff-0488-4bc2-961b-2427925e6a96
< 1.13
HIGH 8.8 The Elementor Addon Elements plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includ… wordfence
2030698f-1180-432b-9a66-3039fdda79fd
< 5.6.2
HIGH 8.8 The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
2022fa8b-2b2a-43a3-9447-90eed326f187
< 1.2.2
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers… wordfence
20033eb0-512f-48ea-8ef7-e22701a2c5d7
< 8.2
HIGH 8.8 The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2… wordfence
1fcd3eec-057a-44f9-a255-e6814a22471b
< 1.2.8
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the Banner Effect Header plugin 1.2.6 for WordPress allows remote att… wordfence
1fc67bb9-178e-466d-a6c2-adaa377924bd HIGH 8.8 The HTML2WP WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could all… wordfence
1fa45912-3d26-4284-8957-5977aaf36a03
< 3.5.0
HIGH 8.8 A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload an… wordfence
1f99b366-1a94-41ed-813a-bb13893604d0
< 4.8.5
HIGH 8.8 The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file … wordfence
1f81d9f2-f7a1-4085-aa20-d991cecacd23
< 4.22
HIGH 8.8 The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempt… wordfence
1f376368-3a1f-4c8a-b14d-142b20f5e57c
< 1.5.5
HIGH 8.8 The RomethemeKit For Elementor plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing cap… wordfence
1f286857-2fd3-4884-982f-47773f7af636 HIGH 8.8 Unrestricted file upload vulnerability in the fusion_options function in functions.php in the Fusion theme 3.1 for Wordp… wordfence
1f25cabc-8886-4d30-af16-07d344db2fff
< 1.9.2
HIGH 8.8 The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parame… wordfence
1e8e0257-a745-495f-a103-c032b95209fc
< 8.3.5
HIGH 8.8 The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8… wordfence
1e8060bc-900f-4f2d-a24e-13dc1d830fc1
< 1.2.10
HIGH 8.8 The Social Rocket plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2… wordfence
1e74b877-45dc-457c-b22c-a0629b305706 HIGH 8.8 The Visual Text Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including,… wordfence
1e47528d-993c-434c-a077-9c614e56f39f HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the PWGRandom plugin 1.11 and earlier for WordPress allow … wordfence
1e3e628f-b5e7-40fd-9d34-4a3b23e1e0e7
< 7.2.8
HIGH 8.8 The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data du… wordfence
1e2423b3-1246-4733-8443-69786d532b4a
< 2.2.0
HIGH 8.8 The Buying Buddy IDX CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
← Prev 197 198 199 200 201 202 203 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top