🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 218 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4b5d1190-3c1e-4cb8-b64b-894ffb1b1f38
< 1.6.2
HIGH 8.3 The Better Find and Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includ… wordfence
4a330416-f867-4a1a-a692-6003e231ed54
< 2.0.1
HIGH 8.3 The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a… wordfence
432807d0-64d8-49b1-a4ab-33aa8fbc5189 HIGH 8.3 The Form Builder plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.9.9.0. This all… wordfence
42b24b41-c520-4bb8-ba56-6f35500ee90e
< 1.9.25
HIGH 8.3 The FooGallery plugin for WordPress is vulnerable to Cross-Site Scripting via the image title and caption parameters in … wordfence
40b57370-4fd7-4316-9e99-a3f1d34616e8
< 1.9.2
HIGH 8.3 The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, … wordfence
3c43939f-c0c7-4388-80ae-44bdf67675c7
< 3.11.4
HIGH 8.3 The WP eCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘sessionid’ parameter in versions up to… wordfence
3b806e11-57ad-4976-9ece-419ad6581cc4
< 4.5.9
HIGH 8.3 The Nelio AB Testing plugin for WordPress is vulnerable to Server Side Request Forgery in versions up to, and including,… wordfence
326618eb-186b-44a2-a779-00d5366bfff2
< 3.0.19
HIGH 8.3 The Essential Grid plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capabilit… wordfence
2dce9e9a-a2f3-49a9-a6bc-00328632c654
< 6.7.7
HIGH 8.3 The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up … wordfence
2d2380af-2ba7-4f6b-a055-52f400042be4
< 2.0.11
HIGH 8.3 The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to Open Redire… wordfence
28e723ee-e99a-4ec4-b492-bfba04d27fd0
< 0.9.91
HIGH 8.3 The WPvivid Backup Plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a m… wordfence
26f431e9-74e0-4920-8766-bf9703e620ee HIGH 8.3 The WP Video Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
25f782c4-7ece-47cb-9e64-9c93fd8858e9
< 1.0.3
HIGH 8.3 The WordPress fancybox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hyperlink’ paramet… wordfence
247e599a-74e2-41d5-a1ba-978a807e6544
< 1.1.5
HIGH 8.3 The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to,… wordfence
1dccb69e-b3d8-44b5-8f5e-931e5afe2bd1
< 3.3.5
HIGH 8.3 The JupiterX Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in version… wordfence
1cda31a4-4c79-4567-a527-6510c31d2843
< 7.4.0
HIGH 8.3 The JS package webpack is vulnerable to Sandbox Bypass in versions up to, and including, 5.75.0 due to mishandling magic… wordfence
1c08b7a7-297b-4ad7-b829-3ccbae7b2e41
< 1.1
HIGH 8.3 The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in… wordfence
0d8a8aa7-8344-4ca7-8194-9bc679d18661
< 3.64.1
HIGH 8.3 An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary… wordfence
0a42449f-aef1-42b8-af58-4f4aab7008f3
< 3.1
HIGH 8.3 The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retriev… wordfence
02665811-15ba-434c-a4d0-df5402a128f4
< 2.10.0.130
HIGH 8.3 The Simple Ads Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.9.… wordfence
01f0f734-b22e-4cd6-be99-ce6c2cd6f2c9
< 7.6
HIGH 8.3 The Indeed Membership Pro plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, … wordfence
01139cbd-1116-4cf8-bdcb-cb182588d093
< 1.45
HIGH 8.3 The BlogVault WordPress Backup Plugin for WordPress is vulnerable to PHP Object Injection in versions 1.40 - 1.44 via de… wordfence
00187815-6706-4ec9-a566-4836de0d17c6
< 4.3.1
HIGH 8.3 There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b… wordfence
f1e98579-6e23-4309-9db5-e47d1e77ab07
< 2.0
HIGH 8.2 The File Download plugin for WordPress has an Open Proxy vulnerability via the 'path' parameter in versions up to, and i… wordfence
eeef2a59-47a1-4d8d-b815-8c74cc608e6c HIGH 8.2 The CommentLuv plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3… wordfence
← Prev 215 216 217 218 219 220 221 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top