ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 220 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6260eb1c-41c0-453d-aee2-be129e566146
< 3.4.9
HIGH 8.2 The Interactive UK Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
59622166-3316-42e5-bf28-69eb38231755
< 1.0.20
HIGH 8.2 The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
4752b3a7-dbb0-4326-bfff-b94dd55b4bf1
< 3.8.12
HIGH 8.2 The Multivendor Marketplace Solution for WooCommerce plugin is vulnerable to Local File Inclusion via the 'wcmp_announce… wordfence
44cd696c-fff3-4942-b2c9-628ba281ba44
< 1.1.2
HIGH 8.2 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification… wordfence
380c646c-fd95-408a-89eb-3e646768bbc5
< 2.8.8
HIGH 8.2 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (… wordfence
33b92a86-bb3e-4307-b2cb-7dfde56505cc
< 1.0.18
HIGH 8.2 The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘searc… wordfence
3208426a-379d-46b9-a9e7-654604169929 HIGH 8.2 The Custom Dashboard Widgets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
2b7ca272-88ac-4002-b4ce-73ad5d0510ef
< 1.4
HIGH 8.2 The Donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. wordfence
23caef95-36b6-40aa-8dd7-51a376790a40
< 3.10.9
HIGH 8.2 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… wordfence
23695c20-d8a1-4aea-92b9-f404e2cdc2fa HIGH 8.2 The Car Park Booking System for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and… wordfence
18458883-6cca-46d1-8437-4e646f4eafda
< 7.0.1
HIGH 8.2 An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbit… wordfence
177a2bda-6c40-4ff6-a53f-e6b2a8408d8a HIGH 8.2 The Fontific | Google Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
0c28545d-c7cd-469f-bccf-90e8b52fd4e7
< 3.2.17
HIGH 8.2 The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions … wordfence
ffe6cbba-1f4e-4cfc-abc8-0349def7bbf5
< 1.0.24
HIGH 8.1 The Booking Calendar Contact Form plugin for WordPress is vulnerable to SQL Injection via the ‘calendar’ atrribute i… wordfence
ffcdd6f7-8bf3-44fd-a095-398f2f98753d
< 1.1.3
HIGH 8.1 The WP Gravity Forms Constant Contact Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions … wordfence
ffc6de82-a4c1-4125-9be0-4fb6de42c178
< 241216
HIGH 8.1 The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions (Pro… wordfence
ffb2820e-a9b3-49a5-bc87-79347720fa7b HIGH 8.1 The Massive Dynamic theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.… wordfence
ffa6b83d-301d-48b2-9670-f7fa599b7ef0 HIGH 8.1 The 69 Clothing | Brand Store & Fashion Boutique WordPress Theme theme for WordPress is vulnerable to PHP Object Injecti… wordfence
ff91999a-e32b-4109-9fc6-bd2a53f30d0f HIGH 8.1 The ShiftCV - Blog \ Resume \ Portfolio \ WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in v… wordfence
ff043947-706b-4107-bd9f-63ce2d6ee665 HIGH 8.1 The Tribe theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.3. This makes … wordfence
feeac2aa-e968-4bae-a7ca-40c0128ad0bb HIGH 8.1 The Marveland theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.0. This ma… wordfence
fe3c8b76-b81e-4fc0-8497-e075cca382d9
< 2.10.3
HIGH 8.1 The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to PHP Object Injection in all ve… wordfence
fe3718a4-79ef-431f-a898-74c37ed3b90d HIGH 8.1 The Navian theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.4. This makes… wordfence
fe3522ff-3eed-4b6a-910a-509b8963e992
< 5.2.3
HIGH 8.1 The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom… wordfence
fe234b62-2a4c-4fa2-a79b-3848e3c68bc9 HIGH 8.1 The Happy Baby theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.12. This … wordfence
← Prev 217 218 219 220 221 222 223 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top