πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 202 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1bd45442-0614-4dd0-bffa-11de68233dd4 HIGH 8.8 The Ultra Demo Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
1bb409f0-ccbd-4dfa-b097-b29ee539daa3
< 1.7.0
HIGH 8.8 The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and in… wordfence
1b948297-7ca1-4c5a-9ade-6b26e7bbcd62
< 2.0.8
HIGH 8.8 The Miraculous Elementor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including… wordfence
1b631b92-b8fb-4f9b-ae2a-bbfd16440ebb HIGH 8.8 The twitterDash plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. … wordfence
1b36fc50-7573-466e-883e-8d26f243c4d0
< 92.0.0
HIGH 8.8 The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f… wordfence
1b2cf896-7cb8-4a1e-bd8c-4da339965138
< 1.3.20
HIGH 8.8 The All Bootstrap Blocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… wordfence
1b2ac807-c6e1-43de-8385-240ccae87e81 HIGH 8.8 The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings,… wordfence
1b29048e-cf06-463c-82e0-f1d973e50232
< 1.35.15
HIGH 8.8 The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,… wordfence
1af5f7be-cfe2-4e0b-ae84-e44095644d84 HIGH 8.8 The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticate… wordfence
1ab0d9f3-0185-41f1-bab5-f47f828fa79c
< 1.0.6
HIGH 8.8 The MiwoFTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. Th… wordfence
1aa7d0c2-27ec-47ad-8baa-c281c273078e
< 2.7.31.2
HIGH 8.8 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all ve… wordfence
1aa7a7f9-f331-4d06-94ea-182535080a90
< 4.6.19
HIGH 8.8 wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPres… wordfence
1a8b22b4-151c-4f42-a0a0-966dc5eb7a9d HIGH 8.8 The PayGreen – Ancienne version plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
1a5f970a-e6a0-4dc7-8e99-342a32f5fd49
< 0.3.6
HIGH 8.8 The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 … wordfence
1a20dc1d-eb7c-47ac-ad9a-ec4c0d5db62e
< 4.8.8
HIGH 8.8 The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions u… wordfence
1a14b86f-a5c8-4ec2-9940-68a37a6c4a86 HIGH 8.8 The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 vi… wordfence
19fe28c0-c0ef-49aa-91c1-2e273201babd
< 9.3.9
HIGH 8.8 The XStore theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a… wordfence
19eec720-a223-422c-8e39-298a5c27b866 HIGH 8.8 The WP shop plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.0. Th… wordfence
19c3d7dd-ccde-463c-abd9-f2c67961251a HIGH 8.8 The iSpring Embedder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
195f86a5-e3dc-4414-bbe3-dea312bf30a9
< 2.0.1
HIGH 8.8 The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incl… wordfence
193c9fe9-17bc-47e7-b93d-dfcebcf8004d
< 31.4
HIGH 8.8 The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability… wordfence
190edd82-840d-4468-8f5a-127cce049336
< 1.6.4
HIGH 8.8 The YITH Request a Quote for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
1900941d-cbb6-4384-977e-6c40f65b2789
< 3.0.8
HIGH 8.8 The plugin My Private Site for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… wordfence
18e8f72b-daa0-4a9f-a67b-d9be9a0862d2
< 3.6.6
HIGH 8.8 The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.5. This… wordfence
18b9e6c0-f1c3-4ef5-b0da-671828508781 HIGH 8.8 The B-Banner Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
← Prev 199 200 201 202 203 204 205 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top