ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 208 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0e30d2ca-1918-4fcf-979e-7cae0d84529e
< 1.2
HIGH 8.8 The Ultimate Category Excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF. wordfence
0e3034ae-957f-410d-80ef-4dc2b0e91ff5
< 1.3.38
HIGH 8.8 The Photo Gallery by 10Web plugin for WordPress is vulnerable to SQL Injection via the ‘album_id’ parameter in versi… wordfence
0dc8f7cf-d8be-4229-b823-3bd9bc9f6eda HIGH 8.8 The WP Simple Galleries plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3… wordfence
0db4671e-1989-44a4-babe-ed699c7f3a52
< 11.4.6
HIGH 8.8 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to… wordfence
0db3f234-111f-4c79-bb54-1a21e4fedb8c
< 4.3.7
HIGH 8.8 The sitepress-multilingual-cms (WPML) plugin before 4.3.7 for WordPress has CSRF due to a loose comparison. This leads t… wordfence
0d794052-1ba2-4772-bc15-5d9732e015e1 HIGH 8.8 The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation… wordfence
0ce2786e-2918-4dc0-99c4-db447216e140
< 1.8.6
HIGH 8.8 The Resize Image After Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
0caf1660-b85e-46e1-9270-a8e14c6bbf52
< 1.5.18
HIGH 8.8 The SpiderVPlayer plugin for WordPress is vulnerable to Multiple Blind Authenticated SQL Injections via the 'order_by' p… wordfence
0c54166e-2af2-409d-8c67-9c07f2028543
< 1.13.4
HIGH 8.8 The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthoriz… wordfence
0c187d78-9f1d-4e55-a611-755ee30f855b
< 11.0.0
HIGH 8.8 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is… wordfence
0c0dd466-a78a-4b79-b9bd-5363f69d9a4c
< 1.6.7.9
HIGH 8.8 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… wordfence
0c06d868-ac71-401a-9b8e-ee04a099c095
< 3.4.2
HIGH 8.8 The Support Board plugin for WordPress is vulnerable to generic SQL Injection via several parameters in versions up to, … wordfence
0c007090-9d9b-4ee7-8f77-91abd4373051
< 7.12.0
HIGH 8.8 The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
0bffed9d-d156-4141-8e0c-112d68dea133 HIGH 8.8 The Arkhe theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.11.0. This… wordfence
0bf117e2-9e59-4028-b77f-7fce2e7174f3 HIGH 8.8 The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… wordfence
0bef7f4a-3a1d-406e-905d-3051f1ee409d
< 2.1.0
HIGH 8.8 The The Pack Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… wordfence
0bb76d11-f16f-4067-a786-37b8e553b609
< 3.3.0
HIGH 8.8 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due… wordfence
0bb43b6c-4f14-401c-9964-1c4c19fc9e51 HIGH 8.8 The Title Field Validation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
0bae0ab5-05c9-41f2-a51d-fb9eaf81e0f8 HIGH 8.8 The Real Estate Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.3… wordfence
0b8dcab4-dd13-4c08-8623-37a50dcbda1b
< 3.9.9
HIGH 8.8 The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to … wordfence
0b787d6f-d002-4f09-8336-ebb91321e20b
< 1.0.98
HIGH 8.8 The Vehica Core plugin for WordPress, used by the Vehica - Car Dealer & Listing WordPress Theme, is vulnerable to privil… wordfence
0b72cf6f-4924-4fa5-8e1a-4054dfe73be0
< 12.1
HIGH 8.8 The Up down image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in ve… wordfence
0b25252b-fad3-4212-be72-94e94779ef67
< 1.6.0
HIGH 8.8 The Structured Content (JSON-LD) #wpsc plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,… wordfence
0b230ff1-4971-4ec5-a0e9-21df90fc6e98
< 2.14.0
HIGH 8.8 The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import me… wordfence
0b08fe5c-dbf4-4c22-a403-f5a6495de2f5 HIGH 8.8 The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could al… wordfence
← Prev 205 206 207 208 209 210 211 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top