ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 335 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bd72ce7e-027c-49bd-8bcf-3ccda2c9b184
< 1.2
HIGH 7.3 The All Video Gallery plugin for WordPress is vulnerable to blind SQL Injection via the ‘ vid’ and 'pid' parameters … wordfence
bbb24ae0-41d6-4d8f-917c-dfd058a7a49d
< 1.2.0.5
HIGH 7.3 The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode exec… wordfence
bad0cd3f-88ea-4a1d-b400-0a450b07a546
< 7.1.6
HIGH 7.3 The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for … wordfence
ba584e02-5242-4869-a452-21e6b8995bd8
< 1.3.3.4
HIGH 7.3 The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in … wordfence
ba52c97e-9f2a-4e48-a133-79ed31cfbf3a HIGH 7.3 HC Custom WP-Admin URL versions up to 1.4 set the admin login slug via the admin_init hook with no capability checks. Th… wordfence
b8133d84-e28c-4132-9eb5-941800320f84
< 5.7.26
HIGH 7.3 The Quick Paypal Payments plugin for WordPress is vulnerable to unauthorized access and modification of data due to a mi… wordfence
b6cf27d9-c0be-4cff-8867-19297f6d79d7
< 4.9.4
HIGH 7.3 The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ… wordfence
b5c6f351-477b-4384-9863-fe3b45ddf21d
< 2.4.2.1
HIGH 7.3 The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to unauthorized access due to mi… wordfence
b524e239-0a7c-4515-8126-4fd298e43bdd
< 2.4.3
HIGH 7.3 The OneLogin SAML SSO plugin for WordPress is potentially vulnerable to SAML Signature Wrapping attack due to use of a l… wordfence
b30ab159-ff3c-4d46-b182-f8938097b837
< 7.2.2
HIGH 7.3 The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPre… wordfence
b1a193b7-21e5-4f57-aaa6-e55c79f8e957
< 5.4.9
HIGH 7.3 The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up … wordfence
b028a70d-f103-4232-b854-17b88d4dc7d9
< 3.0.4
HIGH 7.3 The OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) plugin for WordPress is vulnerable to authorization bypa… wordfence
afffd5e2-798b-42b5-b0b9-ac7d6d06edbb
< 1.5.0
HIGH 7.3 The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable… wordfence
aee6fea2-dbf6-4155-ba3f-f85ea3520504
< 2.10.1
HIGH 7.3 The Beautiful Cookie Consent Banner plugin for WordPress is vulnerable to authorization bypass due to a missing capabili… wordfence
a7faa800-3b29-4b79-8b94-1e7985acb50d
< 1.7.6
HIGH 7.3 The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordP… wordfence
a7e8eb75-ba48-4385-9ddd-800d9bb907f1
< 3.7.15
HIGH 7.3 WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vec… wordfence
a6c842bb-914a-47c1-aaac-e748f58e12ef
< 8.6.8
HIGH 7.3 The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,… wordfence
a3a402f4-3b4d-4397-807b-c5f1c33d52aa
< 1.9
HIGH 7.3 The RokIntroScroller plugin for WordPress is vulnerable to Abuse of Functionality via the 'src' parameter in the 'thumb.… wordfence
a263e79e-b1d4-4f04-8a93-aad6ca76eaf8 HIGH 7.3 The The WP-Asambleas plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and incl… wordfence
a2447cf4-0261-4ef2-98ec-98fa02dc8b87
< 2.2.1
HIGH 7.3 The Flynax Bridge plugin for WordPress is vulnerable to limited Privilege Escalation due to a missing capability check o… wordfence
9d0a8be3-6630-4cf7-b6cb-cdc86b99acb3
< 4.0.2
HIGH 7.3 The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the … wordfence
9c6577a2-6722-4d3b-958d-1143dca414cd
< 2.10.1
HIGH 7.3 The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to… wordfence
9c4e5c12-6f12-40cb-ac0a-389ad3715503
< 0.4.4
HIGH 7.3 The reSmush.it plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several AJ… wordfence
9bb9bab2-4f47-41ed-b42e-5272981927a8
< 1.2.35.2
HIGH 7.3 The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerabl… wordfence
9b8b5363-2450-42b5-8295-78ced3682b14
< 1.26
HIGH 7.3 The WordPress RokStories plugin is vulnerable to Abuse of Functionality via the 'src' parameter in the 'thumb.php' file … wordfence
← Prev 332 333 334 335 336 337 338 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top