ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 10 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f9e2ad4b-716a-4a2d-87c0-2f351bd13884
< 6.0.6
CRITICAL 9.8 The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parame… wordfence
f9d1922d-2bb5-4ed7-849e-781f18828046 CRITICAL 9.8 The WPAMS plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 44.0. This makes … wordfence
f9ced7f4-9574-40a6-94eb-e5d3bdff8336 CRITICAL 9.8 Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slidesh… wordfence
f9b67fc9-87a2-4bd6-a45b-fdfe43ce7ed8
< 1.4
CRITICAL 9.8 Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress… wordfence
f97c669b-86c1-4873-a050-76972f494099
< 1.1.0
CRITICAL 9.8 The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. T… wordfence
f91d6ad6-82fc-4507-90e2-aedfff26bac5 CRITICAL 9.8 The Social Login Lite For WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and… wordfence
f918c749-8c3d-4436-9a84-b040e4a2f8ed
< 3.0.10
CRITICAL 9.8 Blind SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to exec… wordfence
f8f51029-0748-4943-b0ef-fc822b14614a CRITICAL 9.8 The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_inf… wordfence
f8e511ec-93d3-45f3-98ee-ffa7a79bf74e
< 6.9
CRITICAL 9.8 The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to time-based blind SQL Injection via a… wordfence
f8dd7981-e681-425f-9445-f0a28c8af063
< 4.0.2
CRITICAL 9.8 Multiple plugins by ShapedPlugin contain a backdoor in various versions. This makes it possible for unauthenticated atta… wordfence
f8b072a7-ef8a-4f75-994b-1f406d5f9057 CRITICAL 9.8 The Mobile builder plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.4… wordfence
f8aefc77-b5fb-45b0-b3ba-67d850c72e77
< 0.2.2
CRITICAL 9.8 The WP Front End Profile plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 0.… wordfence
f8a54a18-64e2-4046-8143-2b5116c4200b
< 1.5.2
CRITICAL 9.8 The Community Events plugin for WordPress is vulnerable to SQL Injection via the event_category parameter in all version… wordfence
f8698529-4c55-45ad-a0c2-5f1d01944bf0
< 3.6.0
CRITICAL 9.8 The Responsive Tabs with WooCommerce Product Tab Extension plugin for WordPress is vulnerable to authorization bypass du… wordfence
f84c1c45-6930-4865-ba7e-be714f731311
< 1.1.13
CRITICAL 9.8 The Sweet Dessert theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.1.13 via deserialization… wordfence
f83e9ae3-0749-4a61-8a5b-97711145ad98
< 17.1
CRITICAL 9.8 The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p… wordfence
f8259785-b15b-49df-bf9c-9108a6a59070
< 2.4
CRITICAL 9.8 Multiple SQL injection vulnerabilities in the WP-Forum plugin before 2.4 for WordPress allow remote attackers to execute… wordfence
f821e1e2-9114-4b24-bd87-18ab49aa446e
< 1.2.0.2
CRITICAL 9.8 The Annonces plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'th… wordfence
f81a3429-f378-4295-adbe-ad6f1df59701
< 4.5.2
CRITICAL 9.8 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali… wordfence
f816a32a-3c4d-447e-86a3-942b5e636cce
< 1.2.2
CRITICAL 9.8 The JobBoardWP plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in vers… wordfence
f811ce01-8640-4c25-aae1-4f1a35264273 CRITICAL 9.8 The The Fashion - Model Agency One Page Beauty Theme theme for WordPress is vulnerable to PHP Object Injection in all ve… wordfence
f804f31b-4778-4d2d-bcaa-a9f79f6753ee
< 2.5
CRITICAL 9.8 The RT-Theme 18 | Extensions plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… wordfence
f8035ed9-d267-44da-9de4-cf3d6ece7059
< 5.1.3
CRITICAL 9.8 The WP Database Backup plugin for WordPress is vulnerable to unauthenticated settings update that can lead to remote cod… wordfence
f775a263-1817-4da9-8fda-40f3a863a012 CRITICAL 9.8 The PegaPoll plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalati… wordfence
f71f2096-e4c9-406a-a4e5-0006b380fbaa
< 1.9.1
CRITICAL 9.8 The VaultPress plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.9 via the… wordfence
← Prev 7 8 9 10 11 12 13 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top