πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 210 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
08115f30-f38b-4c13-803e-5de873f83a17
< 1.7.4
HIGH 8.8 The Custom Post Type UI plugin for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and includin… wordfence
07fd6bee-5b00-4fc1-9f7a-3857fd35c763 HIGH 8.8 The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc… wordfence
07f6bf26-0b01-48be-bfe1-8213c5d5983f
< 1.12.4
HIGH 8.8 The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for … wordfence
07ea9b9b-e28f-484f-9338-8d40f3f8d6d2
< 1.3.2
HIGH 8.8 The Block WP Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
07ca231c-5b88-4721-a01f-8c135d4cf50b
< 5.6.7
HIGH 8.8 The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
07c0f5a5-3455-4f06-b481-f4d678309c50
< 5.0.10
HIGH 8.8 The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,… wordfence
07c01ab7-8bf8-4aa5-b5e6-8e47a3bf1f7c
< 2.1.0
HIGH 8.8 The wpForo Forum plugin for WordPress is vulnerable to arbitrary file uploads due to missing protections or file validat… wordfence
07aee352-dfef-4762-a93d-e131737d0535 HIGH 8.8 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Image Slider by NextCode plugin <= 1.1.2 at WordPress. wordfence
07abe182-370f-4241-9631-387a7930f2f6 HIGH 8.8 The Gecka Terms Thumbnails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi… wordfence
07a3db33-3787-4b63-835d-8e3026206842
< 4.1.3
HIGH 8.8 The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized mo… wordfence
076f36fb-c2fb-43e0-a027-1351d3995489
< 4.1.17
HIGH 8.8 The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized pl… wordfence
07693689-2f61-41dc-9fa1-b6e5f0073dc5
< 4.0.28
HIGH 8.8 The Church Admin plugin for WordPress is vulnerable to SQL Injection via the 'weeks' value in all versions up to, and in… wordfence
0764d59b-c9bc-4f3c-98df-69ccb7f4bc2d
< 1.58
HIGH 8.8 Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/up… wordfence
07422361-3c7c-4e3c-bbfb-097c7fe5f2b4
< 4.1.21
HIGH 8.8 The Gutenberg Template and Pattern Library & Redux Framework plugin for WordPress is vulnerable to Cross-Site Request Fo… wordfence
0725c0ac-91a7-4359-b911-a450635b09bb
< 1.31.6
HIGH 8.8 The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Cond… wordfence
072092ef-17bc-4b8b-bf8b-bd69a761c56a
< 1.6.9
HIGH 8.8 The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to SQL Injection via … wordfence
06f33e18-0bdd-4c56-a8df-fc1969b9ecf8 HIGH 8.8 The Realia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. Thi… wordfence
06e408f3-3d10-4454-ab71-64f7acd4c850
< 2.66
HIGH 8.8 The pagebar WordPress plugin through 2.65 does not have CSRF check in place when updating its settings, which could allo… wordfence
06c3959a-0b25-4534-b7f6-af561c5aad06 HIGH 8.8 The wordpress-flat-countdown plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… wordfence
06bccd2e-6891-433a-9f5b-3ec0c30afef4 HIGH 8.8 The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validatio… wordfence
06b8d1ce-fd4d-423d-aadf-f114f8a92add HIGH 8.8 SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute ar… wordfence
068cb509-7451-4f2f-a65c-ed7686c6f6d7
< 1.4.7
HIGH 8.8 Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot… wordfence
0677560d-4f2c-4f33-83cc-a958e92852b6
< 5.11.1
HIGH 8.8 The WPJobBoard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 5.11.1. This is due to… wordfence
06513dfe-f263-48b7-ba01-2c205247095b HIGH 8.8 The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
064e7ea2-949e-4f5b-adba-0890f8c6ad25
< 3.1.20
HIGH 8.8 The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification… wordfence
← Prev 207 208 209 210 211 212 213 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top