🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 213 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0153fb37-788e-42f2-9dfa-76418decf1f3
< 1.2.0
HIGH 8.8 The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due… wordfence
014dcf08-1968-4a3f-a772-2248e65dfb07
< 140219
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress… wordfence
010df788-42cf-4455-9f5f-b23d03905afb
< 1.9.15
HIGH 8.8 The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF. wordfence
00f9fd4b-4730-4fa5-80b2-00d97dc72b8e HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactF… wordfence
00f5812d-661e-4206-8c3d-127bc3d48961 HIGH 8.8 The Woocommerce Tabs Plugin, Add Custom Product Tabs plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
00c44ede-326d-48f5-8c78-fe5d566018f3
< 1.3.2
HIGH 8.8 The AWSM Team – Team Showcase Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,… wordfence
00b24f2f-af29-4297-b253-3242dc56542f
< 1.6.8
HIGH 8.8 The Better Find and Replace plugin for WordPress is vulnerable to unauthorized Privilege Escalation due to a missing cap… wordfence
009a6ae4-e9b5-4199-be25-b60e06dc136b
< 4.1.6
HIGH 8.8 The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
009899d4-4139-43ea-a7a1-dc3a1a9ea1e6 HIGH 8.8 The Cross-Linker WordPress plugin through 3.0.1.9 does not have CSRF check in place when creating Cross-Links, which cou… wordfence
005b56c7-55ae-4db0-9ab2-3e22bd8a08ae
< 4.9.2
HIGH 8.8 The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter among others in … wordfence
005a27c6-b9eb-466c-b0c3-ce52c25bb321
< 2.6.1
HIGH 8.8 Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to… wordfence
005234f9-8ae2-455a-8dcd-5d29a6051270
< 1.1.121
HIGH 8.8 The plugin Image Slider is vulnerable to SQL Injection via the post parameter in the function ewic_duplicate_slider in v… wordfence
004e7773-31b9-47e5-a26b-64e75b6b2f9d HIGH 8.8 The Simple Code Insert Shortcode plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1… wordfence
00243844-a2ec-42fd-84d9-03e89619e361
< 1.9
HIGH 8.8 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby’ … wordfence
001c6260-fa3d-49e7-873e-a96c1d6a2e97
< 0.0.7
HIGH 8.8 The Webenvo theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… wordfence
00086b84-c1ec-447a-a536-1c73eac1cc85 HIGH 8.8 The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, le… wordfence
e830fe1e-1171-46da-8ee7-0a6654153f18
< 4.0.2
HIGH 8.7 The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the L… wordfence
d4da8ead-326f-4c93-b56d-8bfa643d7906
< 2.13.5
HIGH 8.7 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… wordfence
69fd1068-4bbd-4e8a-9d35-5e9a072c72e1
< 3.6.1
HIGH 8.7 The Relevanssi plugin for WordPress is vulnerable to generic SQL Injection via the ‘relevanssi_weight_’ parameter in… wordfence
5d94f38f-4b52-4b0d-800c-a6fca40bda3c
< 0.9.90
HIGH 8.7 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, … wordfence
52c24f18-832b-4416-a148-a23e38b257e0
< 2.79.2
HIGH 8.7 The WP-DBManager plugin for WordPress is vulnerable to Directory Traversal allowing arbitrary file deletion in versions … wordfence
364804a5-8699-46be-b25e-890a10134a25
< 9.4.1
HIGH 8.7 The WP Statistics plugin for WordPress is vulnerable to blind SQL Injection via the ‘page-id’ parameter in versions … wordfence
fe0def72-affb-4f42-8857-0e2b8b602c7f HIGH 8.6 Directory traversal in the Media File Organizer (aka media-file-organizer) plugin 1.0.1 for WordPress lets an attacker g… wordfence
fdfb5e74-e52c-4f44-acdc-9740624af9e7
< 3.2.5
HIGH 8.6 The Simple File List plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 3.2… wordfence
eb7e4e96-a4ff-4c6c-91de-c0e5ba78f0da
< 2.0.1
HIGH 8.6 The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized ac… wordfence
← Prev 210 211 212 213 214 215 216 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top