🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 206 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
121a3b46-0b31-4f28-b98e-fc06760548ae
< 1.10.0
HIGH 8.8 The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘d… wordfence
1200d2b3-2c1b-44a4-bf87-2d9b0121d6cb HIGH 8.8 SQL Injection (SQLi) vulnerability in Don Crowther's 3xSocializer plugin <= 0.98.22 at WordPress possible for users with… wordfence
11fd8768-0168-4e3b-9c2d-659fc4101a73
< 4.0.5
HIGH 8.8 The MainWP Google Analytics Extension for WordPress are vulnerable to SQL Injection via an unknown parameter due to insu… wordfence
11d53df8-f7b3-467c-8b3a-515974f1ea69
< 1.5.1.3
HIGH 8.8 SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitra… wordfence
11c369eb-7e5b-4fcf-a526-23466ebad420
< 4.1
HIGH 8.8 SQL injection vulnerability in includes/mode-edit.php in the Simple Retail Menus (simple-retail-menus) plugin before 4.1… wordfence
11bb7190-023b-45e1-99a5-7313c489ef45
< 1.1.9
HIGH 8.8 The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all ver… wordfence
11ba187b-1fe4-4077-ad9d-a07660133e91
< 2.3.29
HIGH 8.8 The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and in… wordfence
11b5f0a1-bf22-46be-a165-c62f1077da0f
< 2.4.7
HIGH 8.8 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions … wordfence
11aaec16-930d-44f6-abe5-4f7fdc32f252
< 6.2.1
HIGH 8.8 The LayerSlider plugin for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including 6.2.0,… wordfence
115f966d-b0f4-46c0-af05-48dd5bf72098
< 3.4.3.19
HIGH 8.8 The WP Shop plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting via the ‘w… wordfence
113dcd4d-e62f-44dc-8087-28d265ef66be
< 1.9.7
HIGH 8.8 The WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php. wordfence
112e4abe-aac7-4fac-b03f-b998374846c4
< 3.0.1
HIGH 8.8 The WP Custom Cursors plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
10e98088-423d-45bb-ae90-51e895d2929b
< 2.8.1.2
HIGH 8.8 The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file uploads due to mis… wordfence
10e49bdd-3a72-4bb7-ba31-21ba4a5b377f
< 4.8.76
HIGH 8.8 The SAML Single Sign On plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
10c65f72-a115-4340-8ed3-ac1e2ce014d2
< 2.09
HIGH 8.8 The Green Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
10c1402d-613d-4d72-b488-c0af2bee4d59
< 1.2
HIGH 8.8 The MathJax LaTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.2. This is due t… wordfence
10a36e37-4188-403f-9b17-d7e79b8b8a6d
< 2.6.0
HIGH 8.8 The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path… wordfence
1091862b-784b-496f-a951-6784544cb51b
< 5.30.5
HIGH 8.8 The YARPP plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.30.4 via the ya… wordfence
107afaa6-6c0b-43fb-9713-ebc4f1189ea6
< 3.2
HIGH 8.8 The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi… wordfence
107a0612-5e58-428b-a097-1c4012e89449 HIGH 8.8 The ACF Images Search And Insert plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v… wordfence
10590944-e08e-4980-846d-7a88880b2dcd
< 4.13
HIGH 8.8 The Accessibility Suite by Online ADA plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… wordfence
1055bba0-7dbd-4382-afaf-ecea442c527c
< 12.7.0
HIGH 8.8 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameter… wordfence
101edd24-3f9e-4055-8547-9cd7e2b626b5
< 1.3.16
HIGH 8.8 The Invite Anyone plugin before 1.3.16 for WordPress has admin-panel CSRF. The plugin’s setting pages had a vulnerabil… wordfence
0ff3a292-3924-4823-867a-fedb2c1cdd00
< 1.4.1.4
HIGH 8.8 Multiple plugins for WordPress with the Jewel Theme Recommended Plugins Library are vulnerable to Unrestricted Upload of… wordfence
0fee990a-8ac0-40a2-9f25-96defd62263d
< 6.3.10
HIGH 8.8 The Theme My Login plugin for WordPress is vulnerable to Local File Inclusion in versions before 6.3.10 via the login_te… wordfence
← Prev 203 204 205 206 207 208 209 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top