🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 10 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fa7e74ee-fd66-41e2-babd-06bdfb32d013
< 4.1.7.2
CRITICAL 9.8 The LearnPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.7.1 via … — wordfence
fa45d830-fa28-4d94-a6d5-2dc2b8456cf2
< 2.0.4
CRITICAL 9.8 The "WordPress Automatic Plugin" plugin for WordPress is vulnerable to generic SQL Injection via the ‘q’ parameter i… — wordfence
fa412364-2e22-439f-8f94-2c525cfbf1a7 CRITICAL 9.8 The Saoshyant Slider plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0 vi… — wordfence
fa2bc3ae-1162-496b-8bc3-5bee1c0ff702
< 1.2.7
CRITICAL 9.8 The Cherry Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and lack of … — wordfence
f9e2ad4b-716a-4a2d-87c0-2f351bd13884
< 6.0.6
CRITICAL 9.8 The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parame… — wordfence
f9d1922d-2bb5-4ed7-849e-781f18828046 CRITICAL 9.8 The WPAMS plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 44.0. This makes … — wordfence
f9ced7f4-9574-40a6-94eb-e5d3bdff8336 CRITICAL 9.8 Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slidesh… — wordfence
f9b67fc9-87a2-4bd6-a45b-fdfe43ce7ed8
< 1.4
CRITICAL 9.8 Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress… — wordfence
f97c669b-86c1-4873-a050-76972f494099
< 1.1.0
CRITICAL 9.8 The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. T… — wordfence
f91d6ad6-82fc-4507-90e2-aedfff26bac5 CRITICAL 9.8 The Social Login Lite For WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and… — wordfence
f918c749-8c3d-4436-9a84-b040e4a2f8ed
< 3.0.10
CRITICAL 9.8 Blind SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to exec… — wordfence
f8f51029-0748-4943-b0ef-fc822b14614a CRITICAL 9.8 The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_inf… — wordfence
f8e511ec-93d3-45f3-98ee-ffa7a79bf74e
< 6.9
CRITICAL 9.8 The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to time-based blind SQL Injection via a… — wordfence
f8dd7981-e681-425f-9445-f0a28c8af063
< 4.0.2
CRITICAL 9.8 Multiple plugins by ShapedPlugin contain a backdoor in various versions. This makes it possible for unauthenticated atta… — wordfence
f8b072a7-ef8a-4f75-994b-1f406d5f9057 CRITICAL 9.8 The Mobile builder plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.4… — wordfence
f8aefc77-b5fb-45b0-b3ba-67d850c72e77
< 0.2.2
CRITICAL 9.8 The WP Front End Profile plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 0.… — wordfence
f8a54a18-64e2-4046-8143-2b5116c4200b
< 1.5.2
CRITICAL 9.8 The Community Events plugin for WordPress is vulnerable to SQL Injection via the event_category parameter in all version… — wordfence
f8698529-4c55-45ad-a0c2-5f1d01944bf0
< 3.6.0
CRITICAL 9.8 The Responsive Tabs with WooCommerce Product Tab Extension plugin for WordPress is vulnerable to authorization bypass du… — wordfence
f84c1c45-6930-4865-ba7e-be714f731311
< 1.1.13
CRITICAL 9.8 The Sweet Dessert theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.1.13 via deserialization… — wordfence
f83e9ae3-0749-4a61-8a5b-97711145ad98
< 17.1
CRITICAL 9.8 The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p… — wordfence
f8259785-b15b-49df-bf9c-9108a6a59070
< 2.4
CRITICAL 9.8 Multiple SQL injection vulnerabilities in the WP-Forum plugin before 2.4 for WordPress allow remote attackers to execute… — wordfence
f821e1e2-9114-4b24-bd87-18ab49aa446e
< 1.2.0.2
CRITICAL 9.8 The Annonces plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'th… — wordfence
f81a3429-f378-4295-adbe-ad6f1df59701
< 4.5.2
CRITICAL 9.8 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali… — wordfence
f816a32a-3c4d-447e-86a3-942b5e636cce
< 1.2.2
CRITICAL 9.8 The JobBoardWP plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in vers… — wordfence
f811ce01-8640-4c25-aae1-4f1a35264273 CRITICAL 9.8 The The Fashion - Model Agency One Page Beauty Theme theme for WordPress is vulnerable to PHP Object Injection in all ve… — wordfence
← Prev 7 8 9 10 11 12 13 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top