πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 204 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
17240c75-4e2a-45d2-8114-414c7e81af87 HIGH 8.8 The Dropshipping & Affiliation with Amazon plugin for WordPress is vulnerable to arbitrary file uploads due to missing f… wordfence
1718f2eb-6235-498f-8c1e-402c1caf7d02
< 2.2.20.2
HIGH 8.8 The Permalink Manager Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
16e6dc49-5edf-4ce4-95c9-19ef04a77379
< 1.8.2
HIGH 8.8 An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF. wordfence
16d0c7ad-e9d3-42c9-ac73-cc8184c9d60d HIGH 8.8 The Restaurant Cafeteria theme for WordPress is vulnerable to unauthorized access due to a missing capability check on t… wordfence
16bce371-b524-48eb-8537-3f9df802abd3
< 4.4
HIGH 8.8 The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all vers… wordfence
16630c5a-802e-404a-b90b-be7b906345b0
< 4.1.5.3
HIGH 8.8 The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered dur… wordfence
16569267-ab52-4b96-86f0-d37c470a3938
< 2.4.7
HIGH 8.8 The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via des… wordfence
1647ac13-d9d1-46ae-93e7-855f55160e03
< 1.4.2
HIGH 8.8 The Organization chart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
1644c2c3-11fa-48d6-ad99-416f27df4483
< 115
HIGH 8.8 The Simple URLs plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in versions up to, and incl… wordfence
1625a77d-bbca-4d18-ae6f-03030ac51d5b
< 1.9.6
HIGH 8.8 The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the p… wordfence
15cf34d8-256b-495e-9385-a5d526bfb335 HIGH 8.8 The Addon Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on… wordfence
15c11a0e-6185-4072-88c6-303090adf898
< 2.0.77.3
HIGH 8.8 In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain ful… wordfence
15b86ae0-93f0-4035-80c3-b3a713077b32 HIGH 8.8 The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settin… wordfence
15a9718f-f877-4e33-8f7a-950791c4ca85
< 2.34.0
HIGH 8.8 The ThemeREX Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.3… wordfence
156b955d-e978-4ff5-ab56-35af257b3199
< 1.5.8
HIGH 8.8 The MailerLite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7.… wordfence
15681d8b-df7b-48c5-bba8-658baf9b9bf1 HIGH 8.8 The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin… wordfence
15654ff3-2e61-44d2-ae3f-4a353db320cb
< 3.0.1
HIGH 8.8 The Smush – Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to deserialization of untr… wordfence
1523db36-fdc6-4a9d-bb2c-d9b28668a3fc HIGH 8.8 The Realestate theme for WordPress is vulnerable to arbitrary file uploads via CSRF due to missing or incorrect nonce va… wordfence
15178478-5208-4869-a9f0-07e8e11ef0d5
< 2.4
HIGH 8.8 The Void Elementor Post Grid Addon for Elementor Page builder plugin for WordPress is vulnerable to Local File Inclusion… wordfence
150021d3-71bb-41c0-bb1c-5843e94ec0b6 HIGH 8.8 The Quasar form plugin for WordPress is vulnerable to SQL Injection via the 'id' shortcode attribute in versions up to, … wordfence
14f0df3e-4333-49d8-a318-6f9fa614c23e
< 1.3
HIGH 8.8 The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set… wordfence
14d81210-9360-4153-9b5a-35d12cc0cbf0
< 1.2
HIGH 8.8 The user-access-manager plugin before 1.2 for WordPress has CSRF. wordfence
14d44753-fbfb-4538-b8ae-0e2a13b14c8e HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the CrossSlide jQuery (crossslide-jquery-plugin-for-wordpr… wordfence
14ad420b-df09-48de-8e36-d8edf0647837
< 2.11.6
HIGH 8.8 The Easy Digital Downloads WordPress plugin before version 2.11.6 does not have Cross-Site Request Forgery checks in pla… wordfence
149fbc16-c35d-4f4b-9bae-13c05451de54 HIGH 8.8 The Crafts & Arts theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5 via de… wordfence
← Prev 201 202 203 204 205 206 207 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top