πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 209 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0b03bca1-84e3-4220-b39b-69044c42e9f9
< 4.6.4
HIGH 8.8 The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… wordfence
0aee8486-59d1-40a2-b200-a6e97318e6ee
< 2.1.1
HIGH 8.8 The MaxiBlocks: 2300+ Patterns, 280+ Pages, 14.3K Icons & 100 Styles plugin for WordPress is vulnerable to unauthorized … wordfence
0aa3ec9b-80d5-4e31-8045-43c8d151cab8
< 8.4.1
HIGH 8.8 The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i… wordfence
0a6c5e9a-754f-41c8-b27b-caa133b5070f
< 1.0.57
HIGH 8.8 The Corner Ad plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.56.… wordfence
0a64e3b3-338d-4cf8-91f3-0ff4732549b4
< 1.2
HIGH 8.8 SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with… wordfence
0a5a0ca6-f355-4110-a533-04e46c741ec9
< 3.0.2
HIGH 8.8 The following plugins for WordPress are vulnerable to Cross-Site Request Forgery: a3 Lazy Load (<= 2.6.0), Contact Us… wordfence
0a56b177-3af4-46ee-93d8-f1a36115f43e
< 1.1.0
HIGH 8.8 The WR Price List Manager For Woocommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… wordfence
0a01e1c9-67f4-4cc1-b58b-9cc141889d66
< 4.0.0
HIGH 8.8 The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inc… wordfence
09ed1806-31b9-4851-99b1-a30eef4979a1
< 4.0.0
HIGH 8.8 The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
09b315e6-d973-467d-8b8d-4b7b4a7ca3f8
< 1.3.1
HIGH 8.8 The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' pa… wordfence
09768e37-7ba8-43b6-93df-3d201fe780ba
< 1.9.2
HIGH 8.8 The Woostify Theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.1. Th… wordfence
095b23b7-71ab-41eb-b666-73df2e1a7eb4
< 1.7.2
HIGH 8.8 The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 v… wordfence
091b2d1d-983a-45ab-935e-635991e8bc8b
< 2.4.1
HIGH 8.8 The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth… wordfence
08fe2e28-5b19-4ce6-914a-304fe82a8ee0
< 2.2.9
HIGH 8.8 The Booking and Rental Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includi… wordfence
08fb698f-c87c-4200-85fe-3fe72745633e
< 13.3
HIGH 8.8 The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcod… wordfence
08f8606a-d590-4836-b634-fa9bd3e59bf4
< 3.3.0
HIGH 8.8 The Houzez theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This i… wordfence
08e9e7f4-0f25-4bc1-85b7-4b504ed38582 HIGH 8.8 The Coditor plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1 via the co… wordfence
08e7125a-0fab-4a4c-8428-127f71847810
< 2.1
HIGH 8.8 The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, a… wordfence
08ba0f2a-f3eb-4d79-abba-99e64df0fe4b
< 4.0.4
HIGH 8.8 In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an admini… wordfence
0886fa16-4292-4223-af01-9aa1f36490f7
< 1.3.15
HIGH 8.8 The Calendar plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcodes in all versions up to, and … wordfence
0867f6a6-17f6-48d3-8ef2-bf89f5b28b05
< 2.6.2.5
HIGH 8.8 The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.… wordfence
0848d526-9530-40f3-8430-499d96b9a1b1
< 1.2.4
HIGH 8.8 Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allow… wordfence
083accd0-8338-47c6-b396-96679b95dd40
< 3.29.1
HIGH 8.8 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and includ… wordfence
0833e55f-22aa-44c9-aff6-1f3b74016e4c
< 1.4.10
HIGH 8.8 The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i… wordfence
0829eb0b-fee2-4522-b06c-be541c6fbef1
< 1.0.10
HIGH 8.8 The Appointment Booking Plugin for WordPress | Efficient Booking, Calendar & Client Scheduling – Bookify plugin for Wo… wordfence
← Prev 206 207 208 209 210 211 212 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top