πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 101 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
05a81b0e-2d25-44b5-b791-5b2aed94bbab CRITICAL 9.8 The MyFTP plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 1.1 due to insuf… — wordfence
0578f4d1-5953-4fbe-8bc3-0569bee57a1a
< 2.7.2
CRITICAL 9.8 The Houzez theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.7.1. This is du… — wordfence
05776ec2-b432-40f6-bd75-4e6ec103c497 CRITICAL 9.8 The Arlo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.0.3. This makes i… — wordfence
056d26da-6e43-4cc6-b2fd-13a5947a814e CRITICAL 9.8 The SAICO theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the php.ph… — wordfence
05544f69-bc9b-4270-80c9-96afe4793cb6
< 1.6.2
CRITICAL 9.8 PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordP… — wordfence
054da118-b268-4dbf-80d3-5ff885f00500 CRITICAL 9.8 The login-social plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, … — wordfence
05431aaa-5d8f-422c-b7ce-955a778f7f55 CRITICAL 9.8 The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive. — wordfence
053bb01c-9e87-4836-ae1c-567272b21118
< 2.0.16
CRITICAL 9.8 The Registration Forms – User Profile, Custom Registration Form, Login Form, Invitation-Based Registrations plugin for… — wordfence
05178bf3-3040-41aa-ba43-779376d30298
< 1.7.6
CRITICAL 9.8 The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5… — wordfence
0502c622-975f-4218-8b53-efd776fe9d99
< 1.0.6
CRITICAL 9.8 The newstatpress plugin before 1.0.6 for WordPress has SQL injection related to an IMG element. — wordfence
04d8b1bf-d514-4908-a30e-6ff7b8e03f82
< 1.2.2
CRITICAL 9.8 The sharebar plugin before 1.2.2 for WordPress has SQL injection via id parameter. — wordfence
04bc8101-2676-4695-a498-f79be8221617
< 2.6.8
CRITICAL 9.8 The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includi… — wordfence
04b7a2ba-e299-4781-8ee6-644938bf9629
< 3.4.5
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization via the api/flu… — wordfence
0491b8b3-014e-4ef2-b3b6-9570063fffc5
< 3.8.3.3
CRITICAL 9.8 The Pie Register Premium plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to 3.8.3.3 (exc… — wordfence
0486fca3-49d4-4edb-9b32-952a20ffa59f
< 2.4
CRITICAL 9.8 The DSK theme for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 2.4. This makes it p… — wordfence
0451a7b8-7657-4b73-9ef1-cc3791349e59
< 1.1.1
CRITICAL 9.8 The Selio - Real Estate Directory theme for WordPress is vulnerable to generic SQL Injection via the β€˜is’ parameter … — wordfence
04033a28-b58a-4584-926b-f43036b23247 CRITICAL 9.8 The Multi Purpose Mail Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… — wordfence
04003542-fd62-4587-9834-70e7fe8f08ef
< 2.0.7
CRITICAL 9.8 The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, … — wordfence
03e853be-510f-4957-a227-17ca9f825b12
< 1.6.1
CRITICAL 9.8 The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all ver… — wordfence
03be4344-d388-4357-8a2e-c3b9c8b83017
< 1.5.6.8
CRITICAL 9.8 The e-signature plugin for WordPress is vulnerable to Remote Code Execution in versions before 1.5.6.8. This allows unau… — wordfence
03b9187e-022a-48c1-a79c-c4629357de5a CRITICAL 9.8 Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contac… — wordfence
038deaeb-633f-49de-92d8-e593ceb47b1e
< 1.0.5
CRITICAL 9.8 The RewardsWP – Loyalty Points & Referral Program for WooCommerce plugin for WordPress is vulnerable to Privilege Esca… — wordfence
038ddfcd-093b-4234-a0b8-a3bf9a3d329f CRITICAL 9.8 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus… — wordfence
0386ed09-296d-4f33-9fe0-964c0c0a9652
< 1.7.0
CRITICAL 9.8 The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation wi… — wordfence
037a8b06-18be-4443-b54c-22f50c89d5b4
< 4.0.9
CRITICAL 9.8 The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues. — wordfence
← Prev 98 99 100 101 102 103 104 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top