🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 100 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
eaafeadd-f44c-49b1-b900-ef40800c629e
< 10.0
CRITICAL 9.1 The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and includ… wordfence
e97c652c-f191-493d-9857-acaa4db8a49a
< 2.0.0
CRITICAL 9.1 Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0… wordfence
e9506f84-3d33-48e0-8dce-d517e1a923e4
< 3.9.0
CRITICAL 9.1 The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the… wordfence
e66ae9e3-7455-4671-9fcb-f0d017ae3346
< 1.10.30
CRITICAL 9.1 The Popup by Supsystic plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including,… wordfence
e4fc23cb-e443-4c8e-b1a0-b8eefbb25dae
< 3.0.4
CRITICAL 9.1 The Edwiser Bridge plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.2 due to in… wordfence
e4bfb72e-023b-4bfd-b125-91f6ac2f200f
< 3.15.4
CRITICAL 9.1 The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path v… wordfence
e30fe90a-774c-41ba-b28e-8b8128fd72cc
< 2.0.1.8.2
CRITICAL 9.1 The Modal Survey plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.1.8 vi… wordfence
e2f9b5ae-bbb9-4b1d-8762-6889a9b8a209
< 4.14.14
CRITICAL 9.1 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to mi… wordfence
e2bb7e1b-0958-47fa-8929-a93ba28d105e CRITICAL 9.1 The WPLMS Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation … wordfence
e074c818-8432-4ee1-a376-0abde3666bc3
< 6.0
CRITICAL 9.1 The Simple User Registration plugin for WordPress is vulnerable to unauthorized access to the user deletion feature due … wordfence
defb87dd-bf5f-411f-b948-699337d05d44
< 6.10.34
CRITICAL 9.1 The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versio… wordfence
dd42c83c-c51c-45a5-8ad5-0df2c0cc411d
< 2.2.2
CRITICAL 9.1 The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab… wordfence
dcb73efb-496a-45eb-882b-1906f05bc3f5
< 1.6.2
CRITICAL 9.1 The HDForms | Contact Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil… wordfence
dbda16f5-65c2-47cf-8b06-6aa231b8fd11
< 3.0.8
CRITICAL 9.1 The Alphabetic Pagination plugin for WordPress is vulnerable to authorization bypass due to a missing capability check o… wordfence
db57971b-57d8-4740-92e0-477a4368bd9b
< 2.9.3
CRITICAL 9.1 The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to arbitrary file deleti… wordfence
d8fb20fb-a795-4ab0-9614-6ae6ac4f2eda
< 2.2.1
CRITICAL 9.1 The Images Optimize and Upload CF7 plugin for WordPress is vulnerable to authorization bypass due to a missing capabilit… wordfence
d8d6684a-5e79-4103-921d-4d997deecd23
< 3.4.07
CRITICAL 9.1 The UiPress lite plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.4.06 due to ins… wordfence
d7d68f43-2a57-4352-8aae-0657b386ac7c
< 4.0.2
CRITICAL 9.1 The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to… wordfence
d7d381af-bb2a-43cb-9e5d-0b3d0e5f88f0
< 2.8.8
CRITICAL 9.1 The Download Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the… wordfence
d65eeb25-8c94-44e9-976d-db5d42e2d06e
< 12.7
CRITICAL 9.1 The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1… wordfence
d5d23a02-11b6-4674-a13a-884de2d51ed7
< 3.8.28
CRITICAL 9.1 The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, lead… wordfence
d5b74a84-e418-4bd4-b36e-5bd4ba5197c9
< 10.8
CRITICAL 9.1 The Salon booking system plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in versions up to… wordfence
d4bbb00b-4baf-4dc1-85ab-3ca3d59eaf33
< 6.1
CRITICAL 9.1 The Easy Forms for Mailchimp for WordPress is vulnerable to Local File Inclusion in versions before 6.1 via the vulnerab… wordfence
d2fdd6eb-c848-446c-abad-7d2ea93f5512
< 4.0.8
CRITICAL 9.1 The WP User Frontend plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, … wordfence
d1a3bc4b-cc17-4728-b242-13841b5f7660 CRITICAL 9.1 The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.… wordfence
← Prev 97 98 99 100 101 102 103 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top