🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 215 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2db8e79f-e70b-421f-8120-7aa65e704deb
< 1.0.5
HIGH 8.6 The MiwoFTP plugin for WordPress is vulnerable to Arbitrary File Download in versions before 1.0.5. This is due to the i… wordfence
27616d9e-c1eb-489f-ace7-76c0e5be2597
< 2.05.03
HIGH 8.6 The Formidable Form Builder plugin for WordPress is vulnerable to SQL Injection via the ‘display-frm-data’ shortcode… wordfence
26e07115-efee-4db5-ba24-25a063286e90
< 4.0.26
HIGH 8.6 The MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution plugin for WordPress is vulnerable to unau… wordfence
091dadcb-71ac-4321-b3aa-72b5fbbd9163 HIGH 8.6 The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing… wordfence
04e2f1f3-95c9-4a90-8c76-7b405a3815f7
< 3.6.16
HIGH 8.6 The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 3.6.15… wordfence
04383919-dae0-4865-b0ff-88049f8cd4db
< 6.2.4
HIGH 8.6 The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP… wordfence
fe7e6a53-36c3-41fc-bae8-a9e1de2494ad
< 1.5.3
HIGH 8.5 The Category Order and Taxonomy Terms Order plugin for WordPress is vulnerable to PHP Object Injection in versions up to… wordfence
f96eb21c-7682-47e3-bd3a-37482d1bd37f HIGH 8.5 The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creatin… wordfence
f1105dc3-222f-46a5-a9b1-74c11923f886
< 2.2.10
HIGH 8.5 The Replyable plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.9 via des… wordfence
e9c2a942-c14c-4b59-92a7-6946b2e4731b
< 1.8.4
HIGH 8.5 The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_con… wordfence
bf70f652-5244-421c-8ee6-75719315ed64
< 1.6.1
HIGH 8.5 The Advanced Contact form 7 DB plugin for WordPress is vulnerable to SQL Injection via the 'acf7db' shortcode in version… wordfence
b01ad77f-2349-48bb-b4e9-f7cbce435de9
< 3.2.12
HIGH 8.5 The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Reque… wordfence
a859505e-87ba-49f0-910b-de6141976f86
< 2.22
HIGH 8.5 The CMS Commander – Manage Multiple Sites plugin for WordPress is vulnerable to PHP Object Injection in versions up to… wordfence
a54038e1-e9e4-48aa-b368-e8d9ec687e85 HIGH 8.5 The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks… wordfence
950a7cc8-c057-41ba-ae2c-e6393cd5a01b
< 1.6.2
HIGH 8.5 The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to SQL Injection in versions up to… wordfence
8de52b68-c273-4561-98b0-e51afd6cd47b
< 2.2.5
HIGH 8.5 The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in ve… wordfence
80064e3b-6996-49eb-a475-0ffe0e894f9e
< 1.11.30
HIGH 8.5 The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and inclu… wordfence
70724bc7-c1f4-4965-8bba-99b2ed21d34b
< 4.4.4
HIGH 8.5 The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all… wordfence
66898509-a93c-4dc3-bf01-1743daaa0ff1
< 1.9.2.2
HIGH 8.5 The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
6417269d-3d49-4f33-b92a-5aacb052bab0
< 3.6.3
HIGH 8.5 The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, … wordfence
5886128e-e72f-4d84-8c17-1ed4a0fcc17e
< 2.6.7
HIGH 8.5 The Spectra plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.6.6 vi… wordfence
55491c64-e4b5-4919-bdcb-7285f2a3c3cd
< 9.1.1
HIGH 8.5 The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode… wordfence
43b11ab0-c7f2-4a7a-aab7-7f9dd58ec1ab
< 7.11.2
HIGH 8.5 The Avada theme for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 7.11.1 via … wordfence
2e78c759-4a54-4ee4-8eff-df91fe9dad46
< 1.2.13
HIGH 8.5 The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' … wordfence
196e629f-7c77-4bcb-8224-305a0108b630
< 2.8.2
HIGH 8.5 The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o… wordfence
← Prev 212 213 214 215 216 217 218 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top