🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 106 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
21389122-cb39-45d1-a889-b830d3a55603
< 3.1.39
CRITICAL 9.1 The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, … wordfence
1fe40943-d2b5-47e9-bc3b-712b5e161099
< 2.5.2
CRITICAL 9.1 The Droip plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all … wordfence
1fcd44c2-5b06-4c3c-b6b2-c58771245fe2
< 1.0.1
CRITICAL 9.1 Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via … wordfence
1dd3e203-dcc4-47b5-ab65-324bcff5b91b
< 7.0.3
CRITICAL 9.1 SQL injection vulnerability in se_search_default in the Search Everything plugin before 7.0.3 for WordPress allows remot… wordfence
19c4d9f5-ffc4-4778-bbf8-2bb770018c3e
< 1.0.65
CRITICAL 9.1 The Oxygen MyData for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file… wordfence
1746da3b-397d-4027-b76d-4c57fadf32c4
< 1.1.1
CRITICAL 9.1 Absolute path traversal vulnerability in the Image Export plugin 1.1 for WordPress allows remote attackers to read and d… wordfence
16dca898-1a98-4e0b-8f48-dc01ba2dc4e6
< 1.1.9
CRITICAL 9.1 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all … wordfence
15f3a6e1-6126-4825-b2b1-e40dc5694f43
< 3.9.2
CRITICAL 9.1 The Atarim - Client Interface plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing c… wordfence
15880d3b-87de-4b59-878c-e36e73c45e8a CRITICAL 9.1 The WPRecovery plugin for WordPress is vulnerable to SQL Injection via the 'data[id]' parameter in all versions up to, a… wordfence
15494ccf-7c9d-4566-9e80-2da94172a3dd
< 2.4.0
CRITICAL 9.1 The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
14ff5609-2345-4073-8239-0ce27fa0957c
< 1.8.11
CRITICAL 9.1 The Slider by Supsystic plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.8.10… wordfence
14877ff6-e393-41a3-91c1-fe7f477297cc CRITICAL 9.1 The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path… wordfence
13c03af2-0bd8-4e81-8ae9-2d702da71fc8 CRITICAL 9.1 The Simple Photo Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘item’ parameter in ver… wordfence
12e2645c-7df1-4fbe-baa1-6b932062682b CRITICAL 9.1 The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion. wordfence
120e6a19-fae3-4083-a72e-36867e7eb18a CRITICAL 9.1 The Advanced XML Reader plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in versions up to, and… wordfence
0ee4fe34-e6ae-4f37-a1a7-ebb153ae7a67 CRITICAL 9.1 The Realia plugin for WordPress is vulnerable to Arbitrary Post Deletion in versions up to, and including, 1.4.0. This i… wordfence
0e656123-cae4-4e0c-a80a-98526be293a8 CRITICAL 9.1 The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a funct… wordfence
0cee20a7-3730-4ee8-85db-79d9d2e9e4c4
< 3.1.1
CRITICAL 9.1 The Membership For WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pa… wordfence
0af80be2-b80b-4a25-9df6-a8ae75ad9cdd CRITICAL 9.1 An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugi… wordfence
0a540897-694a-43d1-bdd8-5aeb07389a51
< 3.0
CRITICAL 9.1 SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 fo… wordfence
097a9d0f-fa38-4fdc-9048-43dd65e7652c
< 1.10.0
CRITICAL 9.1 The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability chec… wordfence
07fc1249-a50d-4038-8cbe-35ff7a3d28b3
< 0.8.9.6
CRITICAL 9.1 The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversa… wordfence
072b66dd-a5d3-46b5-92ec-9cc83b8ea8ef CRITICAL 9.1 The WP Testimonial Widget plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1 … wordfence
04bfad0d-9c6d-41b6-8c59-516eceef9a36 CRITICAL 9.1 WordPress Portable phpMyAdmin Plugin version 1.5.0 and below has an authentication bypass vulnerability. wordfence
0395b775-a89d-45f5-ac38-d5786f4b4d1b
< 1.9.3.6
CRITICAL 9.1 The Gravifyforms plugin for WordPress is vulnerable to blind SQL Injection via the ‘sort_column GET’ parameter in ve… wordfence
← Prev 103 104 105 106 107 108 109 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top