πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 104 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
682a7439-d10a-48b7-84c5-60ac00cf7879
< 3.0.6
CRITICAL 9.1 The Paid Memberships Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.5 due… wordfence
66af88ab-716f-43c9-8c05-148c3f14f676 CRITICAL 9.1 The PT Luxa Addons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio… wordfence
654b28a2-36e7-4226-abda-5c666e54c2de CRITICAL 9.1 The E-xact | Hosted Payment | plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pat… wordfence
63922c28-0cb5-4abe-85ee-20b2cc6f015d
< 0.0.9
CRITICAL 9.1 The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory… wordfence
6215fa9f-06bc-4dc8-b1f5-a3bb75749f1d
< 4.9.9.1
CRITICAL 9.1 The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a… wordfence
5feb08ff-3e1a-4a5c-88d9-1c07409d0c8c
< 7.3.1
CRITICAL 9.1 The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to arbitrary file deletion… wordfence
5bb962bd-9b23-4820-885e-d8095250c3c7
< 2.5.3
CRITICAL 9.1 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletio… wordfence
594c9b09-6abc-4028-889d-46b5394b368a
< 3.1
CRITICAL 9.1 The Litho theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all v… wordfence
5731b971-4408-4c64-809c-e95fba33009e CRITICAL 9.1 The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid… wordfence
554fb91b-35eb-43c4-b949-4f07143e013f
< 6.2.1
CRITICAL 9.1 The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to arbitrary fi… wordfence
53adbab6-953a-4a6f-bbfc-89efdbdd28e0
< 3.28.26
CRITICAL 9.1 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modifi… wordfence
511f64df-4389-4ad7-b2a4-12dc57714631 CRITICAL 9.1 The Advanced Page Visit Counter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.… wordfence
4e6b9ced-b303-43fe-8622-a32685f0a4ea
< 2.10.1
CRITICAL 9.1 The Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… wordfence
49fcd2cb-d880-4152-a736-33fd90f07083
< 1.1.3
CRITICAL 9.1 The WP Child Theme Generator plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and inc… wordfence
47cf9b2c-6857-4dbc-b321-1a84c3e5d11f CRITICAL 9.1 The FW Gallery – Photo, video, audio media presentation and management system with players and slideshow plugin for Wo… wordfence
46ab2615-a1eb-4740-836c-781e961252e7 CRITICAL 9.1 The Product Feed on WooCommerce for Google plugin for WordPress is vulnerable to SQL Injection in versions up to, and in… wordfence
46093b88-2f3c-4e06-833c-6a073cafda0f
< 2.7.8.4
CRITICAL 9.1 The Participants Database plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path va… wordfence
446522ea-7cf1-449b-b05c-58eb815142a4 CRITICAL 9.1 The The School Management Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, … wordfence
41fd12b8-8269-484e-a137-a2c9341b27fe
< 3.0.0
CRITICAL 9.1 The CM Download Manager – Simplify file sharing with powerful download management plugin for WordPress is vulnerable t… wordfence
4183c3f7-7794-45f3-8fad-b87ffec3639c
< 1.4.12
CRITICAL 9.1 The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions … wordfence
417186ba-36ef-4d06-bbcd-e85eb9219689
< 5.6.24
CRITICAL 9.1 The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 v… wordfence
3e1f64f5-090a-4961-8490-d34f458a8d44
< 1.1.9
CRITICAL 9.1 The JS Job Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the j… wordfence
3d7af96a-5a3c-4291-a369-f6ed78f72a3f
< 4.1.3
CRITICAL 9.1 The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insuffi… wordfence
3d4cf93d-61af-4721-9751-9891e08ce7b8
< 11.7
CRITICAL 9.1 The WPO365 | LOGIN plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This le… wordfence
3aaa9c58-87da-4221-b687-f365c6bde167
< 7.0
CRITICAL 9.1 The Chauffeur Taxi Booking System for WordPress plugin for WordPress is vulnerable to authenticated bypass in all versio… wordfence
← Prev 101 102 103 104 105 106 107 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top