πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 338 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
55fa8423-9a41-4afe-9401-03d232caa656
< 7.2.2
HIGH 7.3 The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPre… wordfence
53bb0871-343a-4299-9902-682c422152d1
< 8.9.01.001
HIGH 7.3 The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrendere… wordfence
4ff1d12e-1129-40d3-8c29-3a46ffc77872
< 3.0.15
HIGH 7.3 The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
4f726479-c170-4e84-a5a7-2a82d0f62ad0
< 19.9.8
HIGH 7.3 The The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to arbitrar… wordfence
4f1a1171-3d7b-46a4-982e-fe318e3017b7
< 3.9.5
HIGH 7.3 The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versio… wordfence
4a7be578-5883-4cd3-963d-bf81c3af2003
< 3.3.04
HIGH 7.3 The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and … wordfence
4635f5c1-c326-4f53-bc54-a402cf5dae00
< 5.6.66
HIGH 7.3 The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode e… wordfence
459b7fef-806c-4f5b-bb31-b7197750e941
< 1.4.11
HIGH 7.3 The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing… wordfence
4270a5c2-abc0-4505-9683-030dc08a462d
< 2.7.8
HIGH 7.3 The Feature Image from URL plugin for WordPress is vulnerable to authorization bypass due to missing capability checks o… wordfence
3f2d6c42-4baa-4d15-934f-0f8998c7d654
< 2.3.5
HIGH 7.3 The Post Carousel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on multip… wordfence
3efe6b81-72db-4419-92a3-26e22ebf46e8
< 2.0.13
HIGH 7.3 The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions u… wordfence
3ccd3504-5663-48cd-90bc-502c2ce232f7
< 1.5
HIGH 7.3 The The Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product … wordfence
3c7cc2d2-8de4-453b-b4dc-48f75b151078
< 3.7.4
HIGH 7.3 The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is … wordfence
3bf76527-9a11-4755-992c-02fbc1a79bae HIGH 7.3 The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including… wordfence
37836722-eb25-4393-8cdf-91057642ba3f
< 2.7.4
HIGH 7.3 The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ… wordfence
36b58a4f-0761-4775-9010-9c77d4019c44
< 5.3.15
HIGH 7.3 The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to … wordfence
34c627c1-7838-468e-acb7-eb84ad1b4949
< 14.3.4
HIGH 7.3 The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includ… wordfence
30b6b0bf-e632-4e83-89ee-a424382534da
< 1.5.0
HIGH 7.3 The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and includi… wordfence
3000758d-68e0-46a6-aef0-e2407a828168
< 2.0.0
HIGH 7.3 The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution… wordfence
2e3194a7-5b3d-4805-9a35-50ebe65aa6ae
< 2.6.8
HIGH 7.3 Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspeci… wordfence
2b2769bc-523b-4a8f-9042-1e879db3f8ed
< 2.0.14
HIGH 7.3 The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-regist… wordfence
2ad5544a-6694-41e4-940f-fa96daf4b41d
< 3.1.1
HIGH 7.3 The Checkout with Zelle on Woocommerce plugin for WordPress is vulnerable to unauthorized actions due to a missing capab… wordfence
2a0f539c-5d1d-4e1b-9a4b-719c096ba23c
< 1.16.8
HIGH 7.3 The The NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN plugin … wordfence
2735f9a5-3f5b-4eac-a19a-59925c1fe1b5
< 3.3
HIGH 7.3 Unspecified vulnerability in the Image News slider plugin before 3.3 for WordPress has unspecified impact and remote att… wordfence
266032a8-a139-4a14-8eda-8be7a66357df HIGH 7.3 The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid… wordfence
← Prev 335 336 337 338 339 340 341 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top