πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 339 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
24aa6c0b-88bc-4c3e-ada7-2e89d84bdfc3
< 1.2.17
HIGH 7.3 The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode ex… wordfence
2481f37b-a220-435d-9b43-6e7c5f42034f
< 3.7.18
HIGH 7.3 The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in Wor… wordfence
22cc6da1-fd22-4b2a-90ab-24086879f0f6 HIGH 7.3 The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all version… wordfence
2144ba9f-cb0a-4b54-a23f-3ecb2548a490
< 3.7.31
HIGH 7.3 WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary… wordfence
1f2f390b-332b-452c-9fe7-ccd1a45390dd
< 7.11.14
HIGH 7.3 The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode executi… wordfence
1df6d436-c183-4ace-bd6c-1f22fbe7240f
< 1.16.3.6
HIGH 7.3 Import and export users and customers WordPress Plugin through 1.16.3.5 allows CSV injection via a customer's profile. wordfence
1be557db-daa8-4d86-819a-462f29da884b
< 1.6.8.7
HIGH 7.3 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to a… wordfence
18498171-7db1-4ebb-8fe0-a66d9343cb46
< 3.3.24
HIGH 7.3 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to limited … wordfence
1816a385-0b50-4f0d-848c-f583c247c8fc
< 6.2.20
HIGH 7.3 The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it i… wordfence
15b2a08f-2122-4eaf-ab46-1945cf6a68ca
< 6.2.5
HIGH 7.3 The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an… wordfence
120fa415-81e3-4084-8943-df83cde334c5
< 2.8.3
HIGH 7.3 Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthoriz… wordfence
10d92d5e-1c23-4f6a-bfab-0756876190a5
< 2.7.4
HIGH 7.3 The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all version… wordfence
0cac1dc0-87dc-43eb-9db1-638a91200b43
< 1.3.6
HIGH 7.3 The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary s… wordfence
0ae3cf36-ca3a-4f6d-90c3-6fb67c6862b9
< 2.12.1
HIGH 7.3 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
0935ede4-05bc-48a2-94a3-8d92002e02bb
< 2.3.0
HIGH 7.3 The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin f… wordfence
0747b104-5be6-44eb-b62c-0026f810573c
< 6.1.5
HIGH 7.3 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in versions before 6.1.5. This… wordfence
067031e8-6aa8-451c-a318-b1848c7a4f92
< 3.3.41
HIGH 7.3 The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up … wordfence
032e775a-97be-4d93-bac3-094e35be4b11 HIGH 7.3 The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up … wordfence
fff9fee5-3dca-447d-b7a8-981a5818ec12
< 1.3.6
HIGH 7.2 The Simple Events Calendar for WordPress is vulnerable to SQL Injection via the β€˜event_id’ parameter in versions bef… wordfence
fff57224-f597-4501-b33c-e04061bd0b1a
< 2.2.9
HIGH 7.2 The Prague plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.8 due… wordfence
ffd44a71-486b-4182-bd91-e31dd06d0d4d HIGH 7.2 The Orders functionality in the WP iCommerce WordPress plugin through 1.1.1 has an `order_id` parameter which is not san… wordfence
ffbf5930-50f3-44ca-8333-7b934dcd5ef7 HIGH 7.2 The Simple Buttons Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Add Button" functi… wordfence
ff7ead53-4b20-48ba-95cd-118fb4eab330
< 5.21
HIGH 7.2 The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
ff3aa112-bee2-485f-b5a1-ad156662ab03
< 2.0.8
HIGH 7.2 The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it… wordfence
ff1d2bd8-cc46-4763-8ba7-832b982ff56a
< 5.1.1
HIGH 7.2 The Invisible Anti-Spam & CAPTCHA β€” reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored C… wordfence
← Prev 336 337 338 339 340 341 342 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top