ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 98 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c79a173d-b9c3-4554-95e7-2a4b87382079 CRITICAL 9.6 The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, whic… wordfence
b5490dd9-20d5-4cd6-bc09-5da94d3e702f
< 4.1.5.3
CRITICAL 9.6 The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discov… wordfence
a50531df-e876-463c-a06b-16b2f30aeefe
< 3.7.29
CRITICAL 9.6 WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated use… wordfence
9e6365ab-30c5-4bec-a5f3-b0812ae8a609
< 2.4.1
CRITICAL 9.6 The New User Approve WordPress plugin before 2.4.1 does not have CSRF check in place when updating its settings and addi… wordfence
9e3f199b-b75d-43a2-a20c-957fb1b512e1 CRITICAL 9.6 The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache image… wordfence
92d59dd4-7338-40ac-9a73-37e9e85351d7
< 3.1.1
CRITICAL 9.6 Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.1.0 and earlier allow remote attacker… wordfence
8f4ae82c-f249-4094-a0ef-568c3a30d16b CRITICAL 9.6 The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, wh… wordfence
8df77bb7-4453-403d-8d35-66251f6d399c CRITICAL 9.6 The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allo… wordfence
8b776a8a-b071-4caf-9e67-6f08ace4da2a
< 2.5
CRITICAL 9.6 The ND Booking plugin for WordPress is vulnerable to arbitrary options update in versions up to, and including 2.4, due … wordfence
82acefe0-a839-4721-858d-120326e45664
< 3.1.4
CRITICAL 9.6 The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make… wordfence
812d99bc-8d86-44a9-bafa-be8ce979229c
< 3.7.10
CRITICAL 9.6 Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers t… wordfence
7ffac29d-d1cc-4d5d-aff8-0cb639a1e3d7
< 2.8.5
CRITICAL 9.6 EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving … wordfence
7ea13a80-c744-4de3-ac19-178b67e1afc4 CRITICAL 9.6 The MyAnime Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
7817a840-325a-4709-8374-84bb32d98d0e
< 1.25.0
CRITICAL 9.6 The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.… wordfence
6eb3ad80-3510-4018-91af-b733ef62e28f
< 2.1
CRITICAL 9.6 The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
65b2b72a-5c76-463e-9513-26b400b40a65 CRITICAL 9.6 The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its setting… wordfence
655e6486-e35f-4e7b-b894-55606d3eba56
< 1.5
CRITICAL 9.6 The WP Fast Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4… wordfence
63b67652-d10e-4a5a-97d5-04e6c848b752
< 1.7.2
CRITICAL 9.6 The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin befo… wordfence
5b3f4ccb-fcc6-42ec-8e9e-03d69ae7acf2
< 4.9.1
CRITICAL 9.6 The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as … wordfence
585d0368-7557-46aa-9ea3-26cd6d7df51b
< 4.57
CRITICAL 9.6 The SP Project & Document Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
5717b835-7feb-4bb8-8f1b-1f44d4630cd3
< 3.4.5
CRITICAL 9.6 The Ali2Woo Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.… wordfence
2fd58397-7598-4d98-a6b3-c5837cb3b73e
< 1.5.7
CRITICAL 9.6 The Armour Honeypot Anti Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce vali… wordfence
2be6c7d8-6dd4-4701-9baa-694496e7388a CRITICAL 9.6 The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, whic… wordfence
2b897790-43f7-4ca4-8abe-9dc736a7c011 CRITICAL 9.6 The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which coul… wordfence
25199281-5286-4d75-8d27-26ce215e0993
< 4.9.1
CRITICAL 9.6 The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9… wordfence
← Prev 95 96 97 98 99 100 101 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top