πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 214 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e6d40b41-540d-476d-afde-970845543933
< 7.8.4
HIGH 8.6 The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Informat… wordfence
e005861c-3ca5-4cee-a84b-9ebc095f4a1f
< 1.8.6
HIGH 8.6 WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot … wordfence
cf326914-6a38-4984-a2a7-66e05f41a96b
< 3.3.3
HIGH 8.6 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPres… wordfence
c9955d65-afb3-4d28-abd2-9f2fec92d013
< 2.5.7
HIGH 8.6 The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the… wordfence
c694f5e5-43eb-453c-98d7-0d575d53df1a
< 2.10.36
HIGH 8.6 CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPr… wordfence
bb1742fd-7f0c-4a14-aa9c-f2863fcccd17
< 8.0.0
HIGH 8.6 The Revive Old Posts – Social Media Auto Post and Scheduling Plugin for WordPress is vulnerable to Authorization Bypas… wordfence
b988a8bb-0def-4469-8f97-d329967cb11b HIGH 8.6 The FAT Services Booking plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 5.6 d… wordfence
b71e6219-09cc-484e-8c48-536797d974ce
< 3.3.4
HIGH 8.6 The WordPress WP-Advanced-Search plugin for WordPress is vulnerable to unauthenticated database export in versions up to… wordfence
b5b5d36d-02de-4569-b2cf-addc122ebe34
< 1.5.1
HIGH 8.6 Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote… wordfence
b2fe5315-37b7-4009-b2e5-909e6b5ed1da HIGH 8.6 The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when incl… wordfence
b09c6da0-14d8-4e44-95bd-b5b6b0df97e9
< 0.9.5
HIGH 8.6 The W3 Total Cache plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 0… wordfence
afd9046c-5b6a-411e-8e66-ff1ba60d7f9d
< 4.0.26
HIGH 8.6 The MultiVendorX plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of da… wordfence
a438d058-ccca-4a36-a2e6-40c2b33f2389 HIGH 8.6 The Product Catalog – Catalog for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to,… wordfence
92644676-add4-415c-9a1a-c6616108688d
< 2.1.2
HIGH 8.6 The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and incl… wordfence
89f6f1cd-91ab-416b-b76b-162b3b29d752
< 2.7.2
HIGH 8.6 The JS Help Desk plugin for WordPress is vulnerable to generic SQL Injection via an unknown parameter in versions up to,… wordfence
88d27385-9b92-419c-9e03-687d7192bbb5 HIGH 8.6 The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check wh… wordfence
7fc72cff-b708-4fa2-a734-481446641a61 HIGH 8.6 The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection. wordfence
77db827d-9afd-4b59-b0ad-1ad562634c52
< 2.14.0
HIGH 8.6 The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… wordfence
62687f24-4be2-49de-9a7d-265325b0f72b HIGH 8.6 The Dewplayer plugin <= 1.2 and Advanced Dewplayer plugin < 1.5 for WordPress are vulnerable to Content Spoofing/Injecti… wordfence
5782439f-a546-45f6-aec7-e600442d3c41
< 1.2.8
HIGH 8.6 The AnyWhere Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and inclu… wordfence
577de987-b526-4d7a-8163-683ec3b77bec
< 2.9.5
HIGH 8.6 The ListingPro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.4 due to insuff… wordfence
53bffb82-b9df-40a0-947b-ecae512f363a
< 1.4.8
HIGH 8.6 WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry. wordfence
4e835b97-c066-4e8f-b99f-1a930105af0c
< 5.7.10
HIGH 8.6 The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modificat… wordfence
44158748-798e-4b17-9deb-f54520779c62
< 3.3.14
HIGH 8.6 The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection. wordfence
3a47cdeb-bd05-4e7e-99dc-dca67064182a
< 1.9.31
HIGH 8.6 The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and includi… wordfence
← Prev 211 212 213 214 215 216 217 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top