🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 105 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f624c9a0-b48f-49f5-ba63-276805904945
< 5.1.3
CRITICAL 9.1 The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.… — wordfence
f529b981-623f-4bd3-9155-ebfab4c65d1d
< 3.2
CRITICAL 9.1 The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all vers… — wordfence
f4831e75-dc0e-4d6f-b2cb-8498d8629319 CRITICAL 9.1 The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val… — wordfence
f28ca2dc-404d-4abf-9d44-1b1f8309e9ee
< 2.0.13
CRITICAL 9.1 The Post Grid plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.0.12. Th… — wordfence
f0c23687-2e79-460a-96eb-7d11bf883ced CRITICAL 9.1 The Pk Favicon Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … — wordfence
ed053a6b-4163-4e82-a180-619a7841899a
< 5.8.0
CRITICAL 9.1 The WP Travel Engine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.9 due to … — wordfence
eccc47cb-9078-405b-9b09-2e14e72ee005
< 2.0.3
CRITICAL 9.1 The Import XML and RSS Feeds plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and in… — wordfence
ecbc7f05-fc4f-4276-968e-04222a64e55a
< 4.5.5
CRITICAL 9.1 The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in ve… — wordfence
eb562efb-eb17-4366-9f6d-02653df6ece1
< 1.8.25
CRITICAL 9.1 Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options im… — wordfence
ead5b943-731d-484a-a6b0-ca4f27eccff0
< 4.9.6
CRITICAL 9.1 The Newsletters plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … — wordfence
eaafeadd-f44c-49b1-b900-ef40800c629e
< 10.0
CRITICAL 9.1 The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and includ… — wordfence
e97c652c-f191-493d-9857-acaa4db8a49a
< 2.0.0
CRITICAL 9.1 Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0… — wordfence
e9506f84-3d33-48e0-8dce-d517e1a923e4
< 3.9.0
CRITICAL 9.1 The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the… — wordfence
e66ae9e3-7455-4671-9fcb-f0d017ae3346
< 1.10.30
CRITICAL 9.1 The Popup by Supsystic plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including,… — wordfence
e4fc23cb-e443-4c8e-b1a0-b8eefbb25dae
< 3.0.4
CRITICAL 9.1 The Edwiser Bridge plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.2 due to in… — wordfence
e4bfb72e-023b-4bfd-b125-91f6ac2f200f
< 3.15.4
CRITICAL 9.1 The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path v… — wordfence
e30fe90a-774c-41ba-b28e-8b8128fd72cc
< 2.0.1.8.2
CRITICAL 9.1 The Modal Survey plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.1.8 vi… — wordfence
e2f9b5ae-bbb9-4b1d-8762-6889a9b8a209
< 4.14.14
CRITICAL 9.1 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to mi… — wordfence
e2bb7e1b-0958-47fa-8929-a93ba28d105e CRITICAL 9.1 The WPLMS Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation … — wordfence
e074c818-8432-4ee1-a376-0abde3666bc3
< 6.0
CRITICAL 9.1 The Simple User Registration plugin for WordPress is vulnerable to unauthorized access to the user deletion feature due … — wordfence
defb87dd-bf5f-411f-b948-699337d05d44
< 6.10.34
CRITICAL 9.1 The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versio… — wordfence
dd42c83c-c51c-45a5-8ad5-0df2c0cc411d
< 2.2.2
CRITICAL 9.1 The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab… — wordfence
dcb73efb-496a-45eb-882b-1906f05bc3f5
< 1.6.2
CRITICAL 9.1 The HDForms | Contact Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil… — wordfence
dbda16f5-65c2-47cf-8b06-6aa231b8fd11
< 3.0.8
CRITICAL 9.1 The Alphabetic Pagination plugin for WordPress is vulnerable to authorization bypass due to a missing capability check o… — wordfence
db57971b-57d8-4740-92e0-477a4368bd9b
< 2.9.3
CRITICAL 9.1 The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to arbitrary file deleti… — wordfence
← Prev 102 103 104 105 106 107 108 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top