πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 336 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9ab55dea-84d5-4ed6-a693-8c8de9b7c7dd
< 2.8.3
HIGH 7.3 Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit… wordfence
99f4f1dc-13a9-4fa0-bdb1-77a0d416c80f
< 1.9.1
HIGH 7.3 The Local Delivery Drivers for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data and modific… wordfence
996ade9c-2531-4f43-87f6-eddb2ce98a12 HIGH 7.3 The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versio… wordfence
988d7b33-f985-4d22-a2db-3922002fcecb
< 2.3.9
HIGH 7.3 The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missin… wordfence
98859214-7acf-4d40-9291-b5669b9614b7
< 2.6.1
HIGH 7.3 The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcod… wordfence
966843d1-64c2-4f49-852c-d362714db823
< 1.2.3
HIGH 7.3 An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordP… wordfence
94f6aab3-49a7-4837-a424-e40e483f3f68
< 3.11.14
HIGH 7.3 The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includi… wordfence
942fffb6-2719-4b70-9759-21b2d50002c5
< 2.7.1
HIGH 7.3 The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data … wordfence
8ffc76d8-b841-4c26-bbc6-1f96664efe36
< 1.4
HIGH 7.3 The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This … wordfence
8d22448b-aa8e-4775-b7c5-e7bae94a3f6d
< 4.1.3
HIGH 7.3 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in… wordfence
8c44361b-dbc5-4534-a1a7-416a47ebabe4
< 1.3.3.5
HIGH 7.3 The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in … wordfence
8b3cfe0a-dcfb-40f3-ba43-4e838c113010
< 2.0.5
HIGH 7.3 The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJ… wordfence
83f2ceee-4422-4ed5-adc7-91bc022ae42d HIGH 7.3 The So-Called Air Quotes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and … wordfence
835b254a-9135-4b9d-8607-7122304601bc HIGH 7.3 The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-su… wordfence
82b78826-b256-4612-a830-d44a9bc97541 HIGH 7.3 The Twigify plugin for WordPress is running a vulnerable version of Twig (1.16.3) in all versions up to, and including, … wordfence
82619274-4339-44ba-b50c-d1194c34b695
< 1.1.7
HIGH 7.3 The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in versions up to, and… wordfence
80b5ca3d-d651-4c8a-8c64-6938d4a03710
< 1.1.0
HIGH 7.3 The Kenta Gutenberg Blocks plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … wordfence
8004a306-4c8f-40e9-accc-a12d65b5f2f9
< 1.2.3
HIGH 7.3 The Woocommerce Support System plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data… wordfence
7fc8436b-f787-41dd-8404-9e85cca38cdf
< 1.7.7
HIGH 7.3 The Video Gallery – YouTube Gallery plugin for WordPress is vulnerable to missing authorization in versions up to, and… wordfence
7f50769c-77b8-42ff-b67d-b9b289fc51da
< 1.5.4
HIGH 7.3 The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up… wordfence
7e289b06-66c8-4d50-a8f7-e07c5ae8f7c8 HIGH 7.3 The Shortcodes AnyWhere plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and i… wordfence
7cff7dc5-23e1-424c-923b-68eef49dec6f
< 4.3.5
HIGH 7.3 The Simple Membership plugin for WordPress is vulnerable to privilege escalation due to missing input validation on the … wordfence
7c33b1cb-6eb1-48cd-b706-5ec270f4ae7e
< 5.9.0
HIGH 7.3 The PGS Core plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing … wordfence
7c1e005f-c0f1-4dff-928b-18919f117048
< 2.2.8
HIGH 7.3 The TK Google Fonts GDPR Compliant plugin for wordPress is vulnerable to unauthenticated plugin settings update in versi… wordfence
7bdebd9c-f6fb-4de7-bd6b-5f52ef34ffb3
< 1.8.2
HIGH 7.3 An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permiss… wordfence
← Prev 333 334 335 336 337 338 339 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top