πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 211 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0638c8f3-070a-4b42-ba58-396f3f259b9d
< 1.2.1
HIGH 8.8 The Responsive Owl Carousel for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up … wordfence
05ce62ce-a02f-431e-95b1-ade38988e3ad
< 3.31.0
HIGH 8.8 The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
0593c20d-3422-4817-9639-614254b609db
< 3.5.0
HIGH 8.8 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalati… wordfence
057abffb-1c52-49ca-8791-ca44f0c5a011
< 4.0.3
HIGH 8.8 The Streamit theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i… wordfence
05481984-7c18-4ec7-8d7c-831809c3e86b
< 8.2.0
HIGH 8.8 Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability … wordfence
05448e64-6179-4409-a197-7cdc3c4f1563
< 0.81
HIGH 8.8 The DrawBlog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 0.81. This is due to mi… wordfence
0542f8bf-8fb1-4c47-89b7-106a6feacca1
< 1.1.3
HIGH 8.8 The WP Mail Log plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … wordfence
053d374e-68b2-4d48-af6d-45087d5ce211 HIGH 8.8 The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which c… wordfence
0534bc03-5d7d-47fe-9c07-c9a61af38df2
< 0.72
HIGH 8.8 SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary … wordfence
0531ca34-5d7b-4071-a1aa-934f14b87728
< 8.2
HIGH 8.8 The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in version… wordfence
052dce55-c02d-4e66-b500-bf6160a5b188
< 4.8
HIGH 8.8 The demon image annotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
051a3967-ef86-49bc-b72c-23e43568fef6
< 7.0.19
HIGH 8.8 The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in version… wordfence
0509aaf1-8aae-42e5-84d3-ea9b431703f3
< 1.2.0
HIGH 8.8 The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin… wordfence
04e64fe3-6502-4303-b1f1-1bd62ca00a9c
< 8.7.4
HIGH 8.8 The MapSVG – Vector maps, Image maps, Google Maps plugin for WordPress is vulnerable to arbitrary file uploads due to … wordfence
04bdc2ef-a7aa-45a7-b600-be832eefa32e
< 5.10.4
HIGH 8.8 The Better Click To Tweet plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
04af8675-1b1e-4f17-9eaf-87b49d8702e4
< 3.5.6.2
HIGH 8.8 The JetFormBuilder β€” Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Remote Code Execution in all ve… wordfence
048e266f-5de5-4bcf-96ae-5c6ff969c5f7
< 1.1.4
HIGH 8.8 The aThemes Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… wordfence
046fde5c-9f11-4f09-a4eb-83c289680a18
< 1.5
HIGH 8.8 The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unite… wordfence
046f11b6-7d1a-4bd3-8250-4c5a50fab3ff HIGH 8.8 The Default Thumbnail Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
045fbe5b-0e63-4820-97a7-017dd72eb73a
< 3.2.20
HIGH 8.8 The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
0459d852-4d6b-4457-ad8d-47a3cddded8b
< 1.4.4
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the wpcr_do_options_page function in WP Comment Remix plugin before 1… wordfence
043f5052-6606-4f0e-a6f2-d7276eb50106
< 1.13
HIGH 8.8 The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page. wordfence
043e8bd1-37e8-422d-98df-606dc17a6db7 HIGH 8.8 The Auto Login using a secure tokenized url. Role wise login restriction. plugin for WordPress is vulnerable to privileg… wordfence
041c4d44-28ee-49a4-8407-367ad2960cf6
< 1.3.4
HIGH 8.8 The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do… wordfence
039b7dcc-fad6-4bc1-b0f9-7e888eb54412
< 1.7.2
HIGH 8.8 The Visual Email Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and inc… wordfence
← Prev 208 209 210 211 212 213 214 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top