🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 212 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
038d1144-81b8-4e4b-b0d5-60516f02dbdf
< 3.3
HIGH 8.8 The WP Airbnb Review Slider plugin for WordPress is vulnerable to SQL Injection via the $tid value in versions up to, an… wordfence
034e77ef-fb3f-4e62-be1b-c56c454c5ba8
< 1.3.5.4
HIGH 8.8 The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugi… wordfence
0311b546-01a4-4be8-97f3-6df6cd79c3fe HIGH 8.8 The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and '… wordfence
02f941bd-c42d-49de-9af0-374db3ce22f3 HIGH 8.8 The WP e-Commerce Style Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
02a6428f-beef-4491-ab5f-130a9e7924c2
< 5.2.3
HIGH 8.8 The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is kn… wordfence
02a283b2-a369-4927-a54a-61f26bee6ace
< 9.1.0.6
HIGH 8.8 The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all v… wordfence
0295711d-5da6-4e28-9151-b0ce762c7eb7
< 1.1.16
HIGH 8.8 The Free Booking Plugin for Hotels, Restaurant and Car Rental is vulnerable to arbitrary file uploads due to missing fil… wordfence
0279eb4e-36e1-4cdd-8afb-b3a71e2c726e HIGH 8.8 The Buddypress Humanity plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
02699ada-f4bf-45c4-89e8-018dfff40ac1
< 2.0.4
HIGH 8.8 The Video Gallery and Youtube Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
02551726-672d-481a-8b77-ec7bf33a22c1 HIGH 8.8 The WP Booklet plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.1.8 due t… wordfence
02540fe4-b690-46ab-b79b-a90c8d796ec4
< 5.12.1
HIGH 8.8 The Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
0238801b-310a-43f9-bcc3-5b572868fc4d HIGH 8.8 The FunnelFormsPro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.8… wordfence
02282e33-7e3e-42e1-a7b0-9b5ad326600d
< 17-07-2019
HIGH 8.8 Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter. wordfence
01f0b785-418e-468c-b9f8-53cd46aca881
< 1.0.34
HIGH 8.8 The Mingle Forum plugin for WordPress is vulnerable to generic SQL Injection in versions up to 1.0.34 due to insufficien… wordfence
01f038d7-2efd-41b2-8f4c-77bab80d8e91
< 1.6.1
HIGH 8.8 The peepso-core plugin before 1.6.1 for WordPress has PeepSoProfilePreferencesAjax->save() privilege escalation. wordfence
01d31d8a-4459-488a-9cbe-92761faa58b4
< 9.1
HIGH 8.8 The Image vertical reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode … wordfence
01cc613a-d0b5-4c8f-8961-8f8aaf63b8ac HIGH 8.8 The Intrepidity theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.1.… wordfence
01c1dd65-4cf9-487f-ae3f-9cfaea177385
< 3.7.0
HIGH 8.8 The Companion Sitemap Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
01bb2c40-989f-46c4-84d3-c7b25a49a631 HIGH 8.8 The FAT Services Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.… wordfence
01ab2ed8-ff2f-41ac-bbbd-d8878fd067d6
< 8.1.1
HIGH 8.8 The Recipe Maker For Your Food Blog from Zip Recipes plugin for WordPress is vulnerable to SQL Injection via the ‘orde… wordfence
01aa00db-43e5-4c8a-a005-77a39ec89c94
< 1.2.6
HIGH 8.8 The MemberPress Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
0195bddf-eafe-45f2-9424-ffa235d9b4dc
< 1.1.1
HIGH 8.8 The Elegant Themes Monarch plugin before 1.2.7 for WordPress has privilege escalation. wordfence
01943559-e05b-4dca-b322-d880b2729ee7
< 7.5.5
HIGH 8.8 The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including,… wordfence
018912c2-befc-403c-8e60-161580e84f55
< 1.2.0
HIGH 8.8 The Event Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1… wordfence
01762804-df33-4c4d-b8f6-d94a1e5b5fc9
< 1.5.3.2
HIGH 8.8 The Slideshow Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
← Prev 209 210 211 212 213 214 215 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top