ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 203 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
18b5777c-d176-4214-81ac-b92188704196
< 1.2.4
HIGH 8.8 The ElegantThemes Extra theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.2.… wordfence
18aafcc3-6493-47f2-903b-148afe620625 HIGH 8.8 The Quietly Insights plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege … wordfence
1899b329-d636-47e4-be87-02dc64028e5e HIGH 8.8 The JS Job Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.2. T… wordfence
189430b2-cf7f-46e3-b5b0-c9515b64e731 HIGH 8.8 The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, … wordfence
18932ef8-c0fe-4423-81bd-2f136451463e
< 1.7.4
HIGH 8.8 The Affiliate Coupons plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.3… wordfence
1878f40e-18f4-448c-bf70-61b4eed1c0ff
< 2.4.5
HIGH 8.8 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress. wordfence
18592ba2-cacb-461d-bacd-bc8f44a6126f
< 2.6.0
HIGH 8.8 The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF. wordfence
185371b1-5c72-424d-a5b8-42c67aa9380c
< 3.3.3
HIGH 8.8 The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitr… wordfence
1850e6bd-04bc-4510-aba9-e51431363231 HIGH 8.8 The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account ta… wordfence
1819f2eb-51ef-4ba4-9137-ab64710fa6c8
< 2.5.63
HIGH 8.8 The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and includin… wordfence
1810e2f1-1a0f-46ad-861d-2e52f0421b94 HIGH 8.8 The Shop Products Filter plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… wordfence
1810cea5-cfca-4699-bf09-0e474d04acb6
< 8.0.1
HIGH 8.8 The Advanced Page Visit Counter plugin for WordPress is vulnerable toSQL Injection in versions up to, and including, 7.1… wordfence
180711f3-1a3b-4b10-9046-e63c0e1b9ab5 HIGH 8.8 The MP3 jPlayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.3… wordfence
17f85a52-7f55-4e11-8be3-f088eaad41b3
< 3.9
HIGH 8.8 The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to t… wordfence
17f411fb-364c-4652-a277-bdfee36325f5
< 8.86.0
HIGH 8.8 The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to Privil… wordfence
17dc6988-bbbe-4997-b5f1-230f8003138e
< 5.9.4.4
HIGH 8.8 The ProfileGrid plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.9.4.3 vi… wordfence
17d12a35-35a1-4f7b-aa03-33ddafe17f5b HIGH 8.8 The Waiting: One-click countdowns plugin for WordPress is vulnerable to time-based SQL Injection via the ‘pbc_down[met… wordfence
17ce0f19-04be-4e76-a332-e153d4703534 HIGH 8.8 The Dr Affiliate plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.3 due to insu… wordfence
17c6a91c-e2a6-4f17-b145-145e9e7a0079
< 7.3.6
HIGH 8.8 The themify-ultra theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.3.5 … wordfence
17c06c83-6707-4233-a1c3-ef4cdcf93982
< 2.0.20
HIGH 8.8 The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
17951f68-8481-477b-a940-cce637f6ec54 HIGH 8.8 The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions u… wordfence
17941fbb-c5da-4f5c-a617-3792eb4ef395
< 6.1.1
HIGH 8.8 The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vuln… wordfence
175d8dc0-fc12-464b-b651-50a060851eb2
< 1.2.1
HIGH 8.8 The Trust Payments Gateway (3DS2) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
174eae70-15d7-4772-8fcd-dc4c0fca5b7d HIGH 8.8 The AnyMind Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1… wordfence
174e6344-3919-4c73-8810-33de379ff463
< 6.2.1
HIGH 8.8 The LayerSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2.0… wordfence
← Prev 200 201 202 203 204 205 206 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top