πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 101 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d0567dc8-7a4c-42f4-bf45-f31a8efaa354
< 3.53.3
CRITICAL 9.1 The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including… wordfence
cf0265cb-d58d-4680-8d5b-9b9334f7721e CRITICAL 9.1 The FW Food Menu – Responsive food menu with ordering & delivery solutions plugin for WordPress is vulnerable to arbit… wordfence
cecf1bcc-ed3e-430c-80d4-d940416eed9a
< 2.1.6
CRITICAL 9.1 The Import XML and RSS Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… wordfence
cc5cee40-32a4-499a-ba34-97e07a276a36 CRITICAL 9.1 The Hostme v2 - Responsive WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuffici… wordfence
cc046b72-692a-4980-90ad-26c8fc2a131a
< 1.3.65
CRITICAL 9.1 The Ultimate Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.64 … wordfence
c9df788e-a92e-4519-9e23-8aed08479b68
< 2.0
CRITICAL 9.1 The User Activity Log plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9 due to i… wordfence
c85fa04e-477e-4ac9-b112-02b2ab18ca32
< 1.9.1
CRITICAL 9.1 The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in versions… wordfence
c7f1ffba-bae2-4f69-ac96-c4570d36eb73
< 7.0.1
CRITICAL 9.1 The Openpos - WooCommerce Point Of Sale(POS) plugin for WordPress is vulnerable to arbitrary file deletion due to insuff… wordfence
c6f3b765-396f-422f-864d-a48bee8c69cb CRITICAL 9.1 The Quicksand Post Filter jQuery Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing… wordfence
c458e6d6-28ba-4465-ace2-5da9e99ca2c7
< 3.9.1
CRITICAL 9.1 The DecaLog plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.9.0 due to insuf… wordfence
c3ccde73-8b88-48f9-8bbd-0392fcc40c81
< 4.9.5
CRITICAL 9.1 The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pa… wordfence
bee2245b-d039-48a7-a9dc-bd6ceac6cac6
< 1.0.7
CRITICAL 9.1 The Contact Form Extender for Divi – Submissions DB & Extra Fields plugin for WordPress is vulnerable to arbitrary fil… wordfence
baa20290-9c01-4f8d-adeb-fbfb15b9d6a9 CRITICAL 9.1 The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl… wordfence
b939ec4c-10c0-4c57-be6a-db443e59e22c CRITICAL 9.1 The WordPress Upload Files Anywhere plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fi… wordfence
b90640d2-d6f4-4c3b-8e9b-038d57f5fd6f
< 4.5.4
CRITICAL 9.1 The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows un… wordfence
b8034a3b-9a25-479d-b0d8-30ed4fd76333
< 7.2.5
CRITICAL 9.1 The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to arbitrary fi… wordfence
b6b0bb48-eb61-4236-a03f-19d5d2084a75 CRITICAL 9.1 The Honeypot for WP Comment plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includi… wordfence
b59b5c41-6173-485e-869d-4165dc18e2bd
< 22.6
CRITICAL 9.1 The Frontend File Manager Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and in… wordfence
b50f98ca-6a51-4de8-9e89-004532ba8f96 CRITICAL 9.1 The Colormix Theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all vers… wordfence
b3da58a5-3b07-4c53-ae20-35b3d7750023
< 1.3.3.3
CRITICAL 9.1 The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in … wordfence
b2ef0410-3f8d-40e1-9188-43ec4e7077cd CRITICAL 9.1 The Disable Comments | WPZest plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.51… wordfence
acb239c2-a105-4430-8451-a6ae852a690f
< 3.3.9
CRITICAL 9.1 The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Expo… wordfence
ac37afa3-c841-44b5-9722-952c4258841d CRITICAL 9.1 The KKProgressbar2 Free – advanced progress bars plugin for WordPress is vulnerable to SQL Injection in all versions u… wordfence
abdca93e-f68d-4a96-8bd7-443ee46ccb5a
< 1.9.0
CRITICAL 9.1 The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat… wordfence
aa66da82-8733-41cb-a276-620577d79e44
< 2.0.4
CRITICAL 9.1 The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.3… wordfence
← Prev 98 99 100 101 102 103 104 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top