πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 106 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d8fb20fb-a795-4ab0-9614-6ae6ac4f2eda
< 2.2.1
CRITICAL 9.1 The Images Optimize and Upload CF7 plugin for WordPress is vulnerable to authorization bypass due to a missing capabilit… — wordfence
d8d6684a-5e79-4103-921d-4d997deecd23
< 3.4.07
CRITICAL 9.1 The UiPress lite plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.4.06 due to ins… — wordfence
d7d68f43-2a57-4352-8aae-0657b386ac7c
< 4.0.2
CRITICAL 9.1 The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to… — wordfence
d7d381af-bb2a-43cb-9e5d-0b3d0e5f88f0
< 2.8.8
CRITICAL 9.1 The Download Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the… — wordfence
d6ad49ff-85eb-4d05-ba23-51d89695add3
< 10.8.2
CRITICAL 9.1 The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and inclu… — wordfence
d65eeb25-8c94-44e9-976d-db5d42e2d06e
< 12.7
CRITICAL 9.1 The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1… — wordfence
d5d23a02-11b6-4674-a13a-884de2d51ed7
< 3.8.28
CRITICAL 9.1 The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, lead… — wordfence
d5b74a84-e418-4bd4-b36e-5bd4ba5197c9
< 10.8
CRITICAL 9.1 The Salon booking system plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in versions up to… — wordfence
d4bbb00b-4baf-4dc1-85ab-3ca3d59eaf33
< 6.1
CRITICAL 9.1 The Easy Forms for Mailchimp for WordPress is vulnerable to Local File Inclusion in versions before 6.1 via the vulnerab… — wordfence
d45a01e5-0e69-4d95-b609-b9002b3776da
< 28.3
CRITICAL 9.1 The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2… — wordfence
d430c863-6af1-4519-b276-3bf7e2b2d3c2
< 3.1.7
CRITICAL 9.1 The Advanced Product Fields Extended for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due t… — wordfence
d2fdd6eb-c848-446c-abad-7d2ea93f5512
< 4.0.8
CRITICAL 9.1 The WP User Frontend plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, … — wordfence
d1a3bc4b-cc17-4728-b242-13841b5f7660 CRITICAL 9.1 The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.… — wordfence
d0567dc8-7a4c-42f4-bf45-f31a8efaa354
< 3.53.3
CRITICAL 9.1 The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including… — wordfence
cf0265cb-d58d-4680-8d5b-9b9334f7721e CRITICAL 9.1 The FW Food Menu – Responsive food menu with ordering & delivery solutions plugin for WordPress is vulnerable to arbit… — wordfence
cecf1bcc-ed3e-430c-80d4-d940416eed9a
< 2.1.6
CRITICAL 9.1 The Import XML and RSS Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… — wordfence
cc5cee40-32a4-499a-ba34-97e07a276a36 CRITICAL 9.1 The Hostme v2 - Responsive WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuffici… — wordfence
cc046b72-692a-4980-90ad-26c8fc2a131a
< 1.3.65
CRITICAL 9.1 The Ultimate Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.64 … — wordfence
c9df788e-a92e-4519-9e23-8aed08479b68
< 2.0
CRITICAL 9.1 The User Activity Log plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9 due to i… — wordfence
c85fa04e-477e-4ac9-b112-02b2ab18ca32
< 1.9.1
CRITICAL 9.1 The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in versions… — wordfence
c7f1ffba-bae2-4f69-ac96-c4570d36eb73
< 7.0.1
CRITICAL 9.1 The Openpos - WooCommerce Point Of Sale(POS) plugin for WordPress is vulnerable to arbitrary file deletion due to insuff… — wordfence
c6f3b765-396f-422f-864d-a48bee8c69cb CRITICAL 9.1 The Quicksand Post Filter jQuery Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing… — wordfence
c458e6d6-28ba-4465-ace2-5da9e99ca2c7
< 3.9.1
CRITICAL 9.1 The DecaLog plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.9.0 due to insuf… — wordfence
c3ccde73-8b88-48f9-8bbd-0392fcc40c81
< 4.9.5
CRITICAL 9.1 The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pa… — wordfence
c2d6e619-c32a-450a-a4a0-1069becabff6
< 1.4.48
CRITICAL 9.1 The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is v… — wordfence
← Prev 103 104 105 106 107 108 109 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top