πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 102 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a9f5eab2-09d9-4d8e-8024-abf02b0f6b86
< 1.1.6
CRITICAL 9.1 The Movie Booking plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… wordfence
a8447fa0-f994-4de3-b6e7-2fe61e06bed1
< 3.3.2
CRITICAL 9.1 The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determi… wordfence
a555da8f-586a-4fb8-9230-9238df73cba4
< 1.1.14
CRITICAL 9.1 The Music Store – WordPress eCommerce plugin for WordPress is vulnerable to SQL Injection in all versions up to, and i… wordfence
a2248ba8-b7d7-4691-bf7c-8b23c24417f7
< 3.2
CRITICAL 9.1 The WP Custom Cursors | WordPress Cursor Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_row' p… wordfence
a147956c-a4d8-4945-997a-9b7cea60f926
< 11.2.0
CRITICAL 9.1 The PitchPrint plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in… wordfence
a125bbf1-8ff6-4f3d-a4fb-caaaefe1df2a
< 1.7.14
CRITICAL 9.1 The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and … wordfence
9e20afee-9336-458e-ab5c-b320c6887b83 CRITICAL 9.1 The 10Web Map Builder for Google Maps plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… wordfence
9cb7bc91-b2e9-4ede-80cf-6b961ac6dcb9
< 0.3.0
CRITICAL 9.1 An issue was discovered in WPGraphQL up to 0.2.3 . By querying the 'users' RootQuery, it is possible, for an unauthentic… wordfence
9affd2b9-9576-435e-931d-f60816af0b91
< 1.7.21
CRITICAL 9.1 The CBX Bookmark & Favorite plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.20… wordfence
9addaa26-46b3-4fbf-8986-0b8c8f2dd286 CRITICAL 9.1 The Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension plugin for WordPress is vulnera… wordfence
9a5ce873-e90b-4bdc-b428-426818ff9a86
< 3.6.8
CRITICAL 9.1 The WP All Import plugin for WordPress is vulnerable to arbitrary code execution in versions up to, and including, 3.6.7… wordfence
9a29aea7-9e22-4edb-80d9-266843a416a5
< 3.15
CRITICAL 9.1 The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any … wordfence
98a274eb-036f-44f1-861d-1cfea0b34d7f
< 4.0.4
CRITICAL 9.1 The LearnPress Export Import plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.3… wordfence
97416640-c076-4f5e-9119-adbca2fcc495 CRITICAL 9.1 Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05 wordfence
9715d1b2-1d82-4f48-89c3-9a389ab31360
< 2.2.70
CRITICAL 9.1 The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ve… wordfence
96e2ba3d-4e6d-42b8-832c-03ef4915cadb
< 2.4.2
CRITICAL 9.1 SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute… wordfence
93d00b7e-cad1-4521-8acf-94818258a9d9
< 1.5.16
CRITICAL 9.1 The Scape - Multipurpose WordPress theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficien… wordfence
901e85b9-0948-4a00-a29f-a726b53ba51b
< 2.35.8
CRITICAL 9.1 The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.35.7 due to… wordfence
8ebb1072-ea05-4914-961d-0d8f20248078
< 3.5.0
CRITICAL 9.1 The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file… wordfence
8cf1889b-c249-4bd7-ae23-2db66ca9d873 CRITICAL 9.1 The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress i… wordfence
8b7e1da1-8e40-4119-894d-43e82e188608
< 1.8.11
CRITICAL 9.1 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici… wordfence
8b0f58b8-46d6-4deb-bfcc-806bb635b060
< 5.3.4
CRITICAL 9.1 The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to SQL Injection in all versio… wordfence
8aa0fffa-475e-4227-9ab1-17ca6fcce529
< 2.1.1
CRITICAL 9.1 In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) hea… wordfence
8a24e409-8aa9-4d18-b428-b202407fdbfe CRITICAL 9.1 The PluginPass – WordPress PRO Plugin/Theme Licensing (Public Alpha) plugin for WordPress is vulnerable to arbitrary f… wordfence
88b8a93b-f34f-4188-8153-ce36b03b6a4c
< 4.9.12
CRITICAL 9.1 The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.11 due to … wordfence
← Prev 99 100 101 102 103 104 105 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top