🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 102 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
034ea306-148f-4a67-abac-a2c6a280745c CRITICAL 9.8 The WP Vehicle Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.… — wordfence
033e8326-38ed-4d36-8a29-06f9c8a5e808
< 2.0.3.2
CRITICAL 9.8 The Wholesale Lead Capture Plugin for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all vers… — wordfence
030b26ac-344f-4919-9d2d-b85e5e1599f6
< 2.8.6
CRITICAL 9.8 The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,… — wordfence
02fe4a33-d059-461c-a03f-b7306ce6193f
< 5
CRITICAL 9.8 The GeoPlaces 4 Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the … — wordfence
02d6e9c3-f040-4a41-a803-4bbe5f86c29b
< 5.4.12
CRITICAL 9.8 The Woffice CRM theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.10. … — wordfence
02cf0e1a-bd12-44b1-9bc5-1a5ec332b000
< 1.2.0
CRITICAL 9.8 The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.13. This is du… — wordfence
02bb12db-0bc9-4c13-918f-1f90b500c165
< 1.4.26
CRITICAL 9.8 The PropertyHive plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.4.25 vi… — wordfence
02b75034-8db1-465b-837e-014e2c2e8b4d
< 2.8.0
CRITICAL 9.8 The Asgaros Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.7.2… — wordfence
02998107-9415-433a-8c64-5838324bdcc3 CRITICAL 9.8 The Essential Real Estate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5… — wordfence
0254726d-ce5b-454c-ab8b-d778beb375d4 CRITICAL 9.8 The Evon theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.4. This makes it … — wordfence
023910d0-c2eb-41cd-9d42-606c4cbb8059
< 1.3.3.3
CRITICAL 9.8 The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Uploa… — wordfence
022f6239-67f2-4680-aeed-34c98c953bea
< 1.0
CRITICAL 9.8 The BJ Lazy Load plugin v0.7.5 for WordPress has Remote File Inclusion vulnerability via TimThumb. — wordfence
0209c6ab-cc49-4929-851d-b12c5decf975
< 7.0
CRITICAL 9.8 The AR For WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… — wordfence
01f4318f-b56b-4a34-987b-05edeee5da69
< 2.2.4
CRITICAL 9.8 The wpForo Forum plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.2.3.… — wordfence
01f287b6-1720-4ece-9141-f906835b8bae
< 6.65
CRITICAL 9.8 Multiple plugins for WordPress are vulnerable to unauthenticated site takeover in various versions. This is due to a we… — wordfence
0152bcc9-6d24-4475-848d-71fe88aa7e2a
< 3.30.3
CRITICAL 9.8 The Leyka plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.30.2. This allo… — wordfence
014f1aae-10a0-4bc8-b176-dbdad94a6ad8
< 5.0.5
CRITICAL 9.8 The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data befor… — wordfence
01427553-bc1d-4927-9110-0facd301d976 CRITICAL 9.8 The Quick Learn plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.1 via d… — wordfence
01404fad-7b5a-485a-b557-c608fe25e6c9
< 3.29.10
CRITICAL 9.8 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i… — wordfence
0111a73e-3d5a-4dd5-8974-dc43aafb5050
< 4.9.9
CRITICAL 9.8 The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in all versions up to 4.9.9 (… — wordfence
010300f9-adef-4958-ac77-6ff981833e9e CRITICAL 9.8 The Blaze Slide Show plugin for Wordpress is vulnerable to arbitrary file uploads due to missing file type validation in… — wordfence
010183f3-d614-4fe7-aa70-56d6b3fc5ddc CRITICAL 9.8 The WizShop plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.2. This mak… — wordfence
00ae6b57-6ce2-4e39-91c9-7b2c5b38124b CRITICAL 9.8 The is-human plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.2 via… — wordfence
005fa621-3c49-4c23-add5-d6b7a9110055
< 2.8.3
CRITICAL 9.8 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… — wordfence
005d1abc-761d-4f9a-bc21-aad63e8efd66
< 1.8
CRITICAL 9.8 The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7… — wordfence
← Prev 99 100 101 102 103 104 105 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top