🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 332 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
96d264fe-e7e1-4eec-b235-9d288bc5a22f
< 1.5
HIGH 7.4 The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on se… wordfence
9652575b-389c-42e3-800a-0f133e0c224b
< 2.07
HIGH 7.4 The Shortcodes by Angie Makes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wc_button’ … wordfence
9495e25d-a5a6-4f25-9363-783626e58a4a
< 1.0.126
HIGH 7.4 The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_admin… wordfence
8ed9a5df-90d0-4abe-be1c-49c50a6b48b3
< 3.4
HIGH 7.4 The Duplicate Page plugin for WordPress is vulnerable to generic SQL Injection via the ‘post' parameter in versions up… wordfence
8d18e1c7-65b6-4c1f-88bf-4014418ff920
< 1.2.3
HIGH 7.4 The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in version… wordfence
8806a1b7-03c9-40a8-a1ef-f122329e0443
< 3.31.0
HIGH 7.4 The FG Joomla to WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter… wordfence
80dfc293-a182-4ed5-9127-6ec788312416
< 1.0.41
HIGH 7.4 The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that red… wordfence
74f0af24-e4d9-4b89-b91e-c6ec3e3918e7
< 1.4.1
HIGH 7.4 The Post to CSV by BestWebSoft plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4… wordfence
747d7649-bdf5-46d0-a496-59cb7eac77ac
< 3.0.12
HIGH 7.4 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and r… wordfence
71da4bd0-79d7-42ec-9e79-3a44411c2313 HIGH 7.4 The Add Subtitle WordPress plugin through 1.1.0 does not sanitise or escape the sub-title field (available only with cla… wordfence
70f2965a-37fe-4b7e-890a-9bf73b5de1c7
< 1.9.10.69
HIGH 7.4 The Better Messages plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to 1.9.10.68. This … wordfence
6b8655a6-f410-480d-8c45-2527b53fa129
< 5.0.1
HIGH 7.4 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to PHP Object Injection in versio… wordfence
65b3baaf-86e4-4dd2-b3eb-84c21eabdd6d
< 0.8.7.5
HIGH 7.4 The WP Fastest Cache plugin for WordPress is vulnerable to blind SQL Injection via the ‘$comment_id’ parameter in ve… wordfence
5ce22e5b-7f5c-41be-a50e-dc8100348122 HIGH 7.4 The Olevmedia Shortcodes for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [button] shortcode … wordfence
5629d479-143d-4a03-ac64-cb304954a5ca
< 3.4.0
HIGH 7.4 The Web To Print Shop : uDraw WordPress plugin up to 3.3.3 does not validate the url parameter in its udraw_convert_url_… wordfence
50298ef3-352d-4fd2-bbb9-a55cfd329837
< 4.0
HIGH 7.4 The Ultimate Affiliate Pro for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions… wordfence
4c30b925-47ca-4e14-a418-d9524648db2a
< 2.10.24
HIGH 7.4 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and incl… wordfence
434a724e-0bc6-4218-8ad4-c52e1880a75f
< 2.3.1
HIGH 7.4 The WP Blog and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in … wordfence
419b20fa-6fea-41d7-9e3d-45ac25b4131f
< 3.8.3
HIGH 7.4 Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow … wordfence
39e90b51-c5f2-4a9f-ace8-6fbc6749557b HIGH 7.4 The YaDisk Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode attributes… wordfence
38cc5a39-6ec3-4ce9-b9ad-d4ca5dafe9a7 HIGH 7.4 The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability… wordfence
36ae4183-5fa7-484c-b858-5df10ae3d3f2
< 1.6
HIGH 7.4 The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp… wordfence
246eea09-abe5-41e9-811e-5cddedbbe01e
< 5.3.6
HIGH 7.4 The iThemes Security plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the… wordfence
1d93db2c-7baf-42d8-9b4a-be91b27221a7
< 4.5
HIGH 7.4 The UX Flat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all… wordfence
12dc9e63-17bb-4755-be3c-ae8b26edd3cd
< 5.9.10
HIGH 7.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
← Prev 329 330 331 332 333 334 335 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top