πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 207 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0fe783fe-994b-4274-b51d-0679657bcf32 HIGH 8.8 The WP Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.4… wordfence
0fe551db-2073-4eeb-83da-9ce8c2c031e1 HIGH 8.8 The Blox Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
0fddf084-2be2-4359-b318-a483dee0bd4e
< 6.4.9.4
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563. wordfence
0fd87512-def0-4e59-aa2d-b166919474f3
< 4.2.2
HIGH 8.8 The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,… wordfence
0fbb1044-dd42-469d-9299-135ef2e609e0
< 4.5
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-ac… wordfence
0fb9b039-eb04-4c27-89eb-1932c9c31962
< 2.51
HIGH 8.8 The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions… wordfence
0fad1834-0ee1-4542-a5a7-55a32861c81d
< 3.0.9
HIGH 8.8 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all vers… wordfence
0f98d063-616e-4c26-ae54-78c8580066ca HIGH 8.8 The VG WooCarousel plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3. Thi… wordfence
0f7c43d4-cf21-4324-bc77-50bdc2c24661 HIGH 8.8 The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in vers… wordfence
0f7a32e2-d481-4b2b-bfad-8748f15140bb
< 1.8.7
HIGH 8.8 The BRW plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8.6. This makes i… wordfence
0f79de56-1db4-44f0-a1fd-d1f0429a4539
< 3.1.20
HIGH 8.8 The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification… wordfence
0f70e1b6-2963-43f6-b60f-65830d030d79 HIGH 8.8 The Global Multisite Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
0f6cca7a-b8ff-4ca5-b813-e611eac07695
< 1.3.8.8
HIGH 8.8 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion … wordfence
0f40a2ff-93e8-4216-b6eb-47058b254ee3 HIGH 8.8 The 3D Work In Progress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
0f2e39b3-c18c-4660-b23d-00790156bc7f
< 3.1.3
HIGH 8.8 The Ultimate Product Catalog plugin for WordPress has multiple vulnerabilities in versions up to, and including, 3.1.2. … wordfence
0f00b138-5c4b-4f75-94b1-82721cba2668
< 3.1.39
HIGH 8.8 The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of… wordfence
0ef8024c-d5e5-4921-a161-01507cb4f2bd
< 4.0
HIGH 8.8 The Crafthemes Demo Import plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a mis… wordfence
0ede0053-f885-40b3-a539-edf8df5f12bf
< 1.3.5
HIGH 8.8 The Accessibility by AllAccessible plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and… wordfence
0ed74f7f-d629-4d07-b73e-eaa78f11ea70 HIGH 8.8 The Find and Replace All plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
0ed683bf-be49-43e9-a1ba-9af7c2bf97b1
< 3.0.16
HIGH 8.8 Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka Wor… wordfence
0e9cd38a-b2cd-4801-a06b-4e965fa72e04 HIGH 8.8 The Flipbox Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5… wordfence
0e8f2dba-9108-4531-8428-e66b406349b6
< 1.1.9
HIGH 8.8 The Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab plugin for WordPress is vulnerable to PHP Object In… wordfence
0e8a4400-1169-4015-ae95-9c3109b728fa
< 1.2.5
HIGH 8.8 The WP Subscription Forms plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1… wordfence
0e7654a1-0020-4bf1-86be-bdb238a9fe0d
< 2.8.4
HIGH 8.8 The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing … wordfence
0e70184f-94b6-4742-b99b-6eec9d28f17c HIGH 8.8 The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized modification of … wordfence
← Prev 204 205 206 207 208 209 210 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top