πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 216 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
02b61eb1-a93f-4437-87de-d698af8ef9f6
< 6.9.4
HIGH 8.5 The Blog2Social plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including 6.9.3 due to… wordfence
00bf8f2f-6ab4-4430-800b-5b97abe7589e
< 7.13.0
HIGH 8.5 The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and … wordfence
39b6a1c7-2f8a-49e9-8807-a53a25524018
< 2.9.28
HIGH 8.4 The Ninja Forms Contact Form plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.2… wordfence
ffa90aae-c512-4e7f-a041-e3e41cb8a1d8
< 3.5.5
HIGH 8.3 The Count per Day plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… wordfence
fd4ac2b0-120a-4e68-bf8d-e039336fe9dc
< 3.7.17
HIGH 8.3 wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed… wordfence
fc9cb292-94cb-4d1e-a0b7-98856db7c28e
< 1.10.8
HIGH 8.3 The Merge + Minify + Refresh plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
fb534d86-c477-4a9c-b048-2fbc002168b2
< 2.7
HIGH 8.3 The module cerdic/csstidy, which is used in several plugins, is vulnerable to Server-Side Request Forgery due to the inc… wordfence
f83f878d-b708-4677-929a-e1ced535d99f
< 3.4.5
HIGH 8.3 The MainWP Child plugin for WordPress is vulnerable to authentication bypass due to insufficient validation on the check… wordfence
f6f26854-7e25-4e64-9f03-916ece6fde03 HIGH 8.3 The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i… wordfence
f53cd4a3-a6db-42c2-b4d8-218071c4bcd4
< 1.0.13
HIGH 8.3 The Premmerce User Roles plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to… wordfence
f1ef067b-e4b4-4174-b6ff-ec94a7afd55d
< 3.8.2
HIGH 8.3 The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail… wordfence
ef1468eb-9b98-4d45-b357-70998ba17de7
< 0.8.24
HIGH 8.3 The UpdraftCentral Dashboard plugin 0.8.23 for WordPress is vulnerable to Server-Side Request Forgery via the font param… wordfence
ed08d248-7467-4a3b-91a2-4286d91b9c50 HIGH 8.3 The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions … wordfence
ebcbeb7c-eadb-4541-94f0-6e85f7f3e6a1 HIGH 8.3 The Homepage SlideShow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
e92f35dc-7e19-464a-bb8a-40a662e2270a
< 3.8.14.4
HIGH 8.3 The WP eCommerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various … wordfence
e51e1cd2-6de9-4820-8bba-1c6b5053e2c1
< 1.0.1
HIGH 8.3 The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This… wordfence
ddb97db0-cbf3-42be-a5c7-12fc2a2bc9e8 HIGH 8.3 The WP Lead Plus X plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.… wordfence
dbc98f55-a8f9-4234-84aa-df38302bf0b8
< 3.0.3
HIGH 8.3 The WooCommerce Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
d5d23fdc-081a-4228-897f-2470a9327887
< 1.3.7
HIGH 8.3 The WooCommerce AJAX Product Filters plugin for WordPress is vulnerable to Arbitrary Settings Update in versions up to, … wordfence
d2a99b86-5eb8-438d-a040-68aba2ffa183
< 2.3.9
HIGH 8.3 The Request a Quote WordPress plugin through 2.3.8 does not validate uploaded CSV files, allowing unauthenticated users … wordfence
ccd85a72-1872-4c4f-8ba7-7f91b0b37d4a
< 3.3.1
HIGH 8.3 The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to CSV injection in versions up to, and in… wordfence
c824823c-68d0-4f41-ac22-c517763357eb
< 2.7.8.6
HIGH 8.3 The Traveler – Travel Booking WordPress Theme for WordPress is vulnerable to both Reflected and Stored Cross-Site Scri… wordfence
c03cf3a2-3be9-44da-a050-a5978eb3eadc
< 2.0.1
HIGH 8.3 The Canto plugin 1.9.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker to make a … wordfence
bb85341a-0253-41b2-992e-9202cb3e0f2d
< 1.6
HIGH 8.3 SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administ… wordfence
ad3de7e6-a080-4ce8-aa27-21e7f8fdb2c7
< 3.6.2
HIGH 8.3 The Fusion Builder plugin for WordPress, an Avada theme core plugin, is vulnerable to Server-Side Request Forgery in ver… wordfence
← Prev 213 214 215 216 217 218 219 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top