πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 272 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
39f12ff1-63ee-4131-a708-49633f22ccd4 HIGH 8.0 The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat… wordfence
34d09086-be33-40cf-b5bf-d6c03cf0b68a
< 6.0.10
HIGH 8.0 The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for … wordfence
2f0e19bc-cc1f-4804-ae81-8aa7905ce037
< 1.0.14
HIGH 8.0 The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the … wordfence
24d14261-e295-4397-bad0-7a4b69b06908
< 2.0
HIGH 8.0 The TablePress plugin for WordPress is vulnerable to CSV Injection in versions up to and including 1.14 via the tablepre… wordfence
1edc84fd-8cb5-4899-9444-1b6ae3144917
< 2.8.5
HIGH 8.0 The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth imp… wordfence
1c23d163-1053-403f-80bc-ea8f76fff4e2
< 4.6.0.4
HIGH 8.0 A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requ… wordfence
0248f829-84de-40b9-bb63-354fbf06472d
< 3.7.39
HIGH 8.0 WordPress Core, in versions up to 6.0.2, is vulnerable to SQL Injection that can be exploited by authenticated users via… wordfence
de476d40-47eb-417f-927f-d80d32745965
< 2.72
HIGH 7.8 The WP-DBManager (aka Database Manager) plugin before 2.72 for WordPress allows remote authenticated users to execute ar… wordfence
92bd8f53-7845-4741-84e7-4930dfa973ea
< 1.5.5
HIGH 7.8 The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection. wordfence
7317d716-39e0-40d6-92a8-e59bd8470e5d
< 1.12.22
HIGH 7.8 The WebDorado "Form Maker by WD" plugin before 1.12.22 for WordPress allows CSV injection. wordfence
57d0991b-f10e-4ab8-a8a2-55bf708eefee
< 6.0.8.1
HIGH 7.8 The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting ma… wordfence
546976ff-eabe-4d24-b106-b8e66b7c2c5a HIGH 7.8 The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a mali… wordfence
361315ff-99ef-4fb2-946f-8ccc307bd3be
< 1.0.5
HIGH 7.8 In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/i… wordfence
25b26369-76e3-44f0-8275-03fc6fc9705c
< 1.3.35
HIGH 7.8 The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or … wordfence
fbf25275-eb33-4581-8602-e8a64ba78692
< 1.9.10
HIGH 7.7 The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the… wordfence
e46ff294-0be1-47c1-8c21-f6242c6f832a
< 1.15.0.1
HIGH 7.7 The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Data Exposure in version 1.15 … wordfence
e414a36f-7212-47b9-8e7f-6bf0ae6518af
< 6.4.2
HIGH 7.7 The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_r… wordfence
e33fcd17-318b-408e-86bf-b4ece46121cc
< 5.0.17
HIGH 7.7 The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Upd… wordfence
d357f92a-3c20-4972-af4d-65053027d31c
< 3.7.21
HIGH 7.7 In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF. wordfence
CVE-2026-2592
< 5.0.16.
HIGH 7.7 The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Upd… nvd
c25412d4-f24c-4e29-9b1f-fa89b0383f64
< 6.5.9
HIGH 7.7 The FS Poster - WordPress Social media Auto Poster & Scheduler plugin for WordPress is vulnerable to SQL Injection in al… wordfence
a2a4b5bb-d3c9-42e0-8714-ae75069c7c3a
< 2.2.3
HIGH 7.7 Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versio… wordfence
9bcdcaa4-c492-4d79-8d18-44802abd02e7
< 7.28
HIGH 7.7 The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of d… wordfence
7d61b06b-6709-4f60-8324-53775dbb3c04
< 3.7.28
HIGH 7.7 In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deletin… wordfence
68fee8cb-476d-4962-b830-59fd823329ac
< 1.9.10.58
HIGH 7.7 The Better Messages plugin for WordPress is vulnerable to Resource Exhaustion in versions up to, and including, 1.9.10.5… wordfence
← Prev 269 270 271 272 273 274 275 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top