πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 99 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
24d08127-67b6-434a-8dbe-233a47854f9b CRITICAL 9.6 The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which coul… wordfence
22b539c8-a6f1-4543-9e63-08ee4d468ee0
< 1.0.5
CRITICAL 9.6 The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not s… wordfence
19b4a27d-d9de-4567-86cd-8ec821ee299a
< 2.5
CRITICAL 9.6 Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote atta… wordfence
0a9b4c03-e7ec-48d6-87fe-67e8a5780703
< 2.2.0
CRITICAL 9.6 The a3 Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
618f644b-a92c-4f7f-aaea-c03ee7d6e0f9
< 2.0.46
CRITICAL 9.4 The Ultimate Member – User Profile, User Registration, Login & Membership Plugin plugin for WordPress is vulnerable to… wordfence
f6f91414-5035-4cab-81ad-18558fe43500
< 2.2.3
CRITICAL 9.3 The Better Search plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and in… wordfence
ca38c423-2df8-4f20-bd95-2ecd84167a7f
< 4.0.1
CRITICAL 9.3 The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password… wordfence
9729ebf5-ef78-4ef4-81d4-165f422c3847
< 7.3.15.727
CRITICAL 9.3 The FV Flowplayer Video Player plugin for WordPress is vulnerable to SQL injection in versions up to, and including, 7.3… wordfence
54a425b0-592a-433d-b9e7-776760536668
< 3.3.1
CRITICAL 9.3 A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-d… wordfence
23d762e9-d43f-4520-a6f1-c920417a2436
< 2.8.9
CRITICAL 9.3 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (… wordfence
224a2d6d-7fdc-43a8-a8c9-26213b604433 CRITICAL 9.3 The WordPress Picture / Portfolio / Media Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in a… wordfence
fdd1359f-ce16-4cfe-a6a8-245a21ad16c9
< 18.5
CRITICAL 9.1 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient … wordfence
fb85aacf-a8cf-4054-97fd-b285fcc2a7f9 CRITICAL 9.1 The WP Pipes plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a… wordfence
faed1198-b8c4-46b1-b6a6-5fc35cd7bdf8
< 2.0.22
CRITICAL 9.1 The Formidable Form Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including,… wordfence
f9de8e90-5bda-4ab1-aa78-2748cd717376
< 2.2.4
CRITICAL 9.1 The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… wordfence
f624c9a0-b48f-49f5-ba63-276805904945
< 5.1.3
CRITICAL 9.1 The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.… wordfence
f529b981-623f-4bd3-9155-ebfab4c65d1d
< 3.2
CRITICAL 9.1 The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all vers… wordfence
f4831e75-dc0e-4d6f-b2cb-8498d8629319 CRITICAL 9.1 The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val… wordfence
f28ca2dc-404d-4abf-9d44-1b1f8309e9ee
< 2.0.13
CRITICAL 9.1 The Post Grid plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.0.12. Th… wordfence
f0c23687-2e79-460a-96eb-7d11bf883ced CRITICAL 9.1 The Pk Favicon Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
ed053a6b-4163-4e82-a180-619a7841899a
< 5.8.0
CRITICAL 9.1 The WP Travel Engine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.9 due to … wordfence
eccc47cb-9078-405b-9b09-2e14e72ee005
< 2.0.3
CRITICAL 9.1 The Import XML and RSS Feeds plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and in… wordfence
ecbc7f05-fc4f-4276-968e-04222a64e55a
< 4.5.5
CRITICAL 9.1 The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in ve… wordfence
eb562efb-eb17-4366-9f6d-02653df6ece1
< 1.8.25
CRITICAL 9.1 Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options im… wordfence
ead5b943-731d-484a-a6b0-ca4f27eccff0
< 4.9.6
CRITICAL 9.1 The Newsletters plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … wordfence
← Prev 96 97 98 99 100 101 102 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top