ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ff32cb12-f010-45ae-97d7-f36ce2003f3c
< 4.9.21
CRITICAL 10.0 The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 4.9.20. This is… wordfence
fdb3c672-0ac4-42e8-951b-e41dc8bd6231 CRITICAL 10.0 The SendGrid for WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4 due… wordfence
fbba822b-172f-4167-bccf-4697a298178e
< 6.3.2
CRITICAL 10.0 The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQ… wordfence
f87019bd-4e33-4832-a9f3-4a93157386f8 CRITICAL 10.0 The BuddyPress Cover plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
f70a3776-947f-4322-9e78-100475ed3d7c
< 2.5.4
CRITICAL 10.0 The JobSearch WP Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi… wordfence
f23d80ae-a686-4e89-a8c0-648289521c58
< 1.10
CRITICAL 10.0 The All-in-One Events Calendar plugin for WordPress is vulnerable to SQL Injection via the “ai1ec_cat_idsâ€, “ai1ec… wordfence
ef2ac5c8-9e76-40b8-a2a4-8cb4291871f2
< 2.1.12
CRITICAL 10.0 An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalat… wordfence
e84d50e1-65fe-4323-981f-e2ae6da0ddab
< 1.1.5
CRITICAL 10.0 The CRM Perks Forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.4 due to i… wordfence
e495507d-7eac-4f38-ab6f-b8f0809b2be4
< 4.2.7.1
CRITICAL 10.0 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' para… wordfence
df4dabd8-b676-4449-ab28-34d73fe0c39a
< 2.4.5
CRITICAL 10.0 The Chatbot with ChatGPT WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and includ… wordfence
dd718d44-4921-4deb-af5a-43e5f3926914
< 2.6.8
CRITICAL 10.0 The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
d9de41de-f2f7-4b16-8ec9-d30bbd3d8786
< 3.11.0
CRITICAL 10.0 The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and in… wordfence
d1429549-2e73-4db3-bc83-98c722a80903
< 7.5.18
CRITICAL 10.0 The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to SQL Injection via the 'form_id' parameter … wordfence
cfbc7f74-89c6-4418-9e1e-12650e179912
< 8.7.01.002
CRITICAL 10.0 The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
cedc575c-ee8f-4c62-bc44-95252a0c8b6f
< 0.1.0.39
CRITICAL 10.0 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due … wordfence
ca88c62d-0f27-40e0-9dd2-21d3d133fda3
< 14.0.31
CRITICAL 10.0 The WZone plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 14.0.10 due to insuffici… wordfence
c2b2671e-0db7-4ba9-b574-a0122959e8fc
< 4.2.7.1
CRITICAL 10.0 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter… wordfence
bcc59efb-5ecd-4822-998c-6c79fbeb4c3a
< 1.6.2
CRITICAL 10.0 SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute… wordfence
b8205bfe-4586-42e9-b4f7-e46947396b6b
< 2.4
CRITICAL 10.0 The I LOVE IT! theme is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in versions up to, and… wordfence
b5a7ddea-76db-4009-83a0-92d9ccfe1da4 CRITICAL 10.0 The CZ Loan Management plugin for WordPress is vulnerable to SQL Injection via the 'selectedperiod' parameter of the 'cz… wordfence
ac167257-c34e-45a2-8647-ed5cdb8dd64d
< 1.9.5
CRITICAL 10.0 The WBW Product Table Pro plugin for WordPress is vulnerable to unauthorized arbitrary SQL Execution due to a missing ca… wordfence
ab8bf2d1-1af4-4ea0-bba9-e65ea1ed5978
< 2.0.10
CRITICAL 10.0 The Opti Marketing plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.9 due t… wordfence
a562a213-9c63-4236-8c2c-c7fadffb5ac4
< 1.2.2
CRITICAL 10.0 The Viral Quiz Maker - OnionBuzz plugin for WordPress is vulnerable to blind SQL Injection via the ‘ob_get_results' aj… wordfence
a303c798-c206-426a-9a96-263c8c069bdb
< 1.3.9
CRITICAL 10.0 The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files… wordfence
a2bda5d0-9589-4925-baa6-6e207e6fc978
< 3.3.0
CRITICAL 10.0 The WP Dummy Content Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 3.3.0 (… wordfence
1 2 3 4 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top