🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 201 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1e1d008d-28a4-4827-8d25-158307382394 HIGH 8.8 The Sinking Dropdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
1e18c00b-fd26-4ac3-adf8-fd52d139e33f
< 2.2.1
HIGH 8.8 The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Privilege Escalat… wordfence
1df74d3d-b7c9-4cf8-b1a7-d2b0b4f706d2
< 3.5.3
HIGH 8.8 The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelis… wordfence
1de36458-d7e5-43cf-af40-0fd7a6eea5bb
< 8.0.8
HIGH 8.8 The WP Support Plus Responsive Ticket System plugin for WordPress is vulnerable to arbitrary file uploads in versions up… wordfence
1dd928cb-5466-424e-a87a-3a9618edb56b
< 3.7.2
HIGH 8.8 The Phone Orders for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
1da18430-1bd0-4f63-9e22-5d26de2be410
< 1.0.7
HIGH 8.8 The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida… wordfence
1d92ce83-03de-4981-8d90-0b8d2a2d16ef
< 1.2.2
HIGH 8.8 The Core Control plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
1d79432d-7977-4279-ac69-8e9db682800e
< 3.2.6.8
HIGH 8.8 LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection wordfence
1d7440ae-f939-478c-8861-57020537dd44
< 0.5.7
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to hijac… wordfence
1d17d3ce-2478-498b-8364-75d2449a9b58
< 2.4.22
HIGH 8.8 The ad-inserter plugin before 2.4.22 for WordPress has remote code execution. wordfence
1d063d01-5f67-4c7f-ab71-01708456e82b HIGH 8.8 The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_settin… wordfence
1cf65f79-d386-4dd4-a360-b2f764dfaf19
< 3.8.2
HIGH 8.8 The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insu… wordfence
1c703856-9519-4181-9312-dcf862840bd9
< 4.2.153
HIGH 8.8 An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated atta… wordfence
1c507681-61e9-4bf0-8fe5-e2f401a7a8be
< 1.8.4.1
HIGH 8.8 The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8… wordfence
1c49f37f-62eb-40ce-9c9e-e7e8785fc114
< 1.2.7
HIGH 8.8 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an… wordfence
1c442d6b-a272-4fb1-8f8e-8cdda326be6d HIGH 8.8 The Push Notifications for WordPress by PushAssist plugin for WordPress is vulnerable to arbitrary file uploads due to m… wordfence
1c3247d1-c230-44f5-8151-355c2078f01b HIGH 8.8 The School Management plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 93.0.… wordfence
1c307340-2911-46b9-9c90-0a7ebad8a0e9
< 1.12
HIGH 8.8 The Smash Balloon Social Photo Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
1c22de8c-e6e1-4b85-8d9f-619e9f63129e
< 1.10.0
HIGH 8.8 The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion i… wordfence
1c2153f5-1c8b-4095-a0a8-849a7ee967c1 HIGH 8.8 Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter. wordfence
1c1ce474-ecce-4d21-b174-cb54a2441b2b
< 9.0.3
HIGH 8.8 The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in v… wordfence
1c1c7ec9-d01f-433d-abec-dc2b6ff684c7
< 2.9.5
HIGH 8.8 The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the re… wordfence
1c0f613e-5ee6-447c-b508-702627223979
< 1.1.3
HIGH 8.8 The Login Widget for Ultimate Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and i… wordfence
1bebb24c-c141-4fcf-8288-9b8faaaf69c9
< 2.1.13
HIGH 8.8 The Team Manager – WordPress Showcase Team Members plugin for WordPress is vulnerable to Local File Inclusion in all v… wordfence
1bdba04e-df4d-4094-877e-611d69e2e25d
< 2.9.4
HIGH 8.8 The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and includi… wordfence
← Prev 198 199 200 201 202 203 204 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top