πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 105 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3a4179ef-c98b-42c9-b7e5-a42bc46eaad1
< 10.6.6
CRITICAL 9.1 The Wp EMember plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… wordfence
3a3b8f32-f29d-4e67-8fad-202bfc8a9918
< 1.8.20
CRITICAL 9.1 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal i… wordfence
386eea84-0b86-46c8-99a2-c73696ae09be
< 1.18
CRITICAL 9.1 The WordPress RokNewsPager plugin is vulnerable to Denial of Service via the 'src' parameter in the 'thumb.php' file in … wordfence
38526b0c-a5d9-4f54-bd6f-30ab34d266f5
< 3.6.16
CRITICAL 9.1 The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 3.6.15 … wordfence
38398f29-1bd7-4f15-9d7e-7ad52264f5c7
< 4.7.5
CRITICAL 9.1 The Noo JobMonster theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… wordfence
366e5302-3edc-4bc8-8d84-9e0ee7abb25a CRITICAL 9.1 The WordPress RokBox plugin is vulnerable to Content Spoofing via the 'file', 'config', and 'abouttext' parameters in th… wordfence
35e2f081-41ca-4465-933a-db5c30b058da
< 2.7.1
CRITICAL 9.1 The WP Easy Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 'galleryId' or 'select_gallery' … wordfence
34f0e5a6-0bd3-4734-b7e0-27dc825d193f
< 7.0.2.1
CRITICAL 9.1 The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… wordfence
32da04ba-bee3-4fd3-b91b-57e588d5f4e4
< 2.2.2
CRITICAL 9.1 The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab… wordfence
3060dbda-97f3-410c-863e-ea76a6a018fd
< 1.11.4
CRITICAL 9.1 The Z-Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … wordfence
2ef0ab24-ec21-4d23-980d-71a23bf20f9e
< 2.2.7
CRITICAL 9.1 The Responsive Ready Sites Importer for WordPress is vulnerable to authorization bypass due missing capability checks on… wordfence
2e0ca51c-0536-45ff-a5af-41ef4977179d
< 1.6.3
CRITICAL 9.1 The SearchWP Live Ajax Search plugin for WordPress is vulnerable to Directory Traversal via the 'swpengine' parameter us… wordfence
2ddfb494-1a63-4958-849e-392eec09615d CRITICAL 9.1 The formcraft plugin for WordPress is vulnerable to Arbitrary File Deletion via the 'function.php' file. This makes it p… wordfence
2d903c78-2c7e-45fb-a8b4-ae060d9a020c
< 1.4
CRITICAL 9.1 The ionCube Tester Plus plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3. … wordfence
2d34b675-ff66-475e-b838-657dd51fc48c
< 6.4.4
CRITICAL 9.1 The Auto Affiliate Links plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.4.3… wordfence
2cf2201d-6da0-4f66-9135-c6b34ef7c65f
< 2.0.7
CRITICAL 9.1 The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to exec… wordfence
2cb1b526-0df6-42a1-9294-90bc61730209
< 7.8.7
CRITICAL 9.1 The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file deleti… wordfence
2a56eb63-ba5c-4452-8ab9-f5aeaf53adda
< 7.27
CRITICAL 9.1 The W3SPEEDSTER plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.26 v… wordfence
27180d98-223a-4d86-b8ea-e47da1d61bbf
< 5.5.16
CRITICAL 9.1 The Live Streaming - Broadcast Live Video Plugin for WordPress is vulnerable to Remote Code Execution in versions up to,… wordfence
26e7dd3f-5bdd-47d2-a013-82db72b4eae6
< 240325
CRITICAL 9.1 The s2Member plugin for WordPress is vulnerable to limited privilege escalation in versions up to, and including, 240315… wordfence
2591af6b-e057-4c17-aeba-5c31efbae622
< 2.5
CRITICAL 9.1 The DejaVu Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.4. This is d… wordfence
24a802cc-bec3-48ac-a2af-34fba3939c17 CRITICAL 9.1 The Global Gateway e4 | Payeezy Gateway | plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici… wordfence
245d89e5-52cc-44b1-a858-0ca0aacb4e26 CRITICAL 9.1 The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in version… wordfence
242ad00b-3602-4988-ab7a-76fba2e9d4cf
< 1.3.0
CRITICAL 9.1 The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insuffi… wordfence
224233bc-68f3-40e4-8182-4831ccce93fb
< 1.29.3
CRITICAL 9.1 The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to SQL Injection … wordfence
← Prev 102 103 104 105 106 107 108 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top