πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 334 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e353d938-8844-41dc-96dc-7e2facf96446 HIGH 7.3 The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX… wordfence
e3499182-7501-4fec-a7c6-b66ae47533cd HIGH 7.3 The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information… wordfence
e278df67-e4d3-416c-ac7d-6e43442dde17 HIGH 7.3 The [GWA] AutoResponder plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up … wordfence
df00c8bc-8acd-4197-86fe-b88cb47d52c3
< 3.0.18
HIGH 7.3 The MasterStudy LMS plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.0.17.… wordfence
dec51bd6-2ffe-47b6-9423-6131395bf439
< 1.4.2.2
HIGH 7.3 The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode… wordfence
dea2d045-d3b4-4b55-8b4f-5baa82a18834
< 2.6.14
HIGH 7.3 The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for … wordfence
de45dd8c-c734-4b14-89ee-dbc46dcdae6a
< 2.0.9
HIGH 7.3 The WP Libre Form 2 plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.0.… wordfence
dd056d29-3bd9-49e4-bcc4-fa487de8a27e
< 8.2.4
HIGH 7.3 The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including… wordfence
d97ed290-b887-4fa5-866c-e7af9b29b517
< 0.1.5
HIGH 7.3 The Content No Cache | Serve uncached partial content even when you add it to a page that is fully cached plugin for Wor… wordfence
d918b6ae-a72c-48dc-885b-19be49d578dc
< 4.3.8
HIGH 7.3 The RealHomes theme for WordPress is vulnerable to unauthorized access due to a missing capability check an unknown func… wordfence
d8a3e69e-b6d2-495a-878d-1c2329e9e553
< 1.9.8.1
HIGH 7.3 SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute a… wordfence
d89cf759-5e5f-43e2-90a9-a8e554653ee1
< 1.9.8
HIGH 7.3 The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability chec… wordfence
d630dd85-0169-4582-a8ae-54e5053425ac
< 2.2.6
HIGH 7.3 The The CURCY – Multi Currency for WooCommerce – The best free currency exchange plugin – Run smoothly on WooComme… wordfence
d35ea739-5ee9-4779-87d5-3f13b11229cf HIGH 7.3 The ORDER POST plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,… wordfence
d32215b5-9ecb-4feb-b76f-18821184dd8b
< 6.4
HIGH 7.3 The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to un… wordfence
d0a311b7-5582-4581-bf4e-636d8a936ac6
< 3.7.1
HIGH 7.3 The WooCommerce Blocks plugins for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.7… wordfence
ceb0dffa-02a2-4193-b2c4-4774091eacfa
< 1.4.2.3
HIGH 7.3 The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode… wordfence
cc4f2fd3-ed6b-4fe4-b300-02b1b35ebb7b
< 3.2.1
HIGH 7.3 The Easy Social Icons plugin for WordPress is vulnerable to Admin+ cross-site scripting and unauthenticated icon deletio… wordfence
cb8bb740-d977-4d5f-a4db-d75b67ff1ed2
< 2.0.4
HIGH 7.3 The The Uix Shortcodes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and in… wordfence
c9b010ff-8a4a-4553-bb2b-d58a254d7ee4
< 3.8.7
HIGH 7.3 The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versio… wordfence
c3d5f51f-6abd-49d0-b8cd-bbe518787ab8
< 2.2.3
HIGH 7.3 Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.3 for WordPress allows remote attackers to… wordfence
c38ac8d6-c6de-4be7-bf7b-198e085a0ad2
< 7.2.0
HIGH 7.3 The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t… wordfence
c1c218c6-1599-4dc9-846f-e0ef74821488
< 3.8
HIGH 7.3 The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to unauthorized modification of da… wordfence
bf48087a-f729-488a-8e40-f4e010ccd5a7
< 1.5.1.3
HIGH 7.3 WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-h… wordfence
be759c83-a9df-4858-a724-28006a595404
< 3.0.15
HIGH 7.3 The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability ch… wordfence
← Prev 331 332 333 334 335 336 337 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top