πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 271 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
00747cde-efb3-486f-ac19-903dee69263d HIGH 8.1 The Ekoterra - NonProfit & Ecology Theme theme for WordPress is vulnerable to Local File Inclusion in versions up to, an… wordfence
00200994-e9a3-4fa2-84b6-b5fd79d4995f
< 1.4.5
HIGH 8.1 The Ziston theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.4.5. This makes it possible for… wordfence
db1bad2e-55df-40c5-9a3f-651858a19b42
< 7.9.9
HIGH 8.0 The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin… wordfence
da082107-1c71-4d18-a864-986807568de9
< 2.6.0
HIGH 8.0 lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPr… wordfence
d482f3a1-4a5a-4382-88b1-fd3b91605694 HIGH 8.0 The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file d… wordfence
c7c7247c-2fc3-46ff-858e-2242b7211476
< 3.9.2
HIGH 8.0 The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. … wordfence
c272f769-65da-4963-aff0-8f68a277ea63
< 3.7.37
HIGH 8.0 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-pri… wordfence
bfd16372-9173-4168-8604-5c117d05c349
< 1.2.4
HIGH 8.0 The Health Check & Troubleshooting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
baafd001-144d-4ee4-b7e6-28c0931e6e10
< 2.11.3
HIGH 8.0 The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl… wordfence
b4fe8b1f-da1c-4f94-9ab4-272766b488c3
< 7.9.9
HIGH 8.0 The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin… wordfence
b0ef885f-fd62-4513-83cb-65381b99a172
< 3.7.37
HIGH 8.0 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to … wordfence
a9b8f2d5-a2c5-4f90-ab1d-4e17f7a7996e
< 5.4.17
HIGH 8.0 The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This … wordfence
a7e35f18-7659-4b97-b99f-b57ac941cb22 HIGH 8.0 The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and … wordfence
a176f206-eb96-4902-8355-eec3c9ff6809
< 1.8.0
HIGH 8.0 The Checkout Field Editor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1… wordfence
9efa04ca-68c8-4221-a3d9-cf75010d2266
< 5.3.7
HIGH 8.0 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… wordfence
93554eb7-2f81-4eb1-809e-6dfe1f5b6196
< 2.1.2
HIGH 8.0 The WPForms User Registration plugin for WordPress is vulnerable to privilege escalation in all versions up to, and incl… wordfence
82f80916-37ab-4c5a-9787-2544c620acac
< 0.9.0.3
HIGH 8.0 The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and i… wordfence
7d8365a6-dfa2-4753-b655-3c2bcadeae75
< 1.6.0
HIGH 8.0 The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows an attacker to c… wordfence
74e5bed8-3c6a-479a-9f2f-f15a467cd896
< 1.3.9
HIGH 8.0 The Contact Form Widget – Contact Query, Contact Page, Form Maker, Query Table plugin for WordPress is vulnerable to S… wordfence
5c517278-9d2a-4ef6-bf0e-a62f6b00dd20
< 1.4.3.2
HIGH 8.0 The 140+ Widgets | Best Addons For Elementor – FREE for WordPress is vulnerable to PHP Object Injection in versions up… wordfence
56b16f10-2f48-49db-85f6-f934bc267110
< 1.0.4
HIGH 8.0 The My WP Translate plugin for WordPress is vulnerable to an authorization bypass weakness in versions up to, and includ… wordfence
50ac32ed-f83c-4afc-aac2-a79c69497091
< 1.20.5
HIGH 8.0 The Import and export users and customers plugin for WordPress is vulnerable to CSV Injection in versions up to, and inc… wordfence
4c3ee9fa-5d66-4f84-818f-ceec2f0c0b96
< 0.6.0
HIGH 8.0 The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and… wordfence
48f148ee-800d-4c8f-bf43-893ec7961f3a
< 1.0.0-beta3
HIGH 8.0 The WordCamp Talks plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.0.0 Beta2 via… wordfence
4658109d-295c-4a1b-b219-ca1f4664ff1d
< 0.9.92
HIGH 8.0 The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in version… wordfence
← Prev 268 269 270 271 272 273 274 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top