πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 107 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bee2245b-d039-48a7-a9dc-bd6ceac6cac6
< 1.0.7
CRITICAL 9.1 The Contact Form Extender for Divi – Submissions DB & Extra Fields plugin for WordPress is vulnerable to arbitrary fil… — wordfence
bdb4468a-cd01-4f4c-9353-d77fcf7a558f
< 1.7.67
CRITICAL 9.1 The Shared Files (Free and Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p… — wordfence
baa20290-9c01-4f8d-adeb-fbfb15b9d6a9 CRITICAL 9.1 The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl… — wordfence
b939ec4c-10c0-4c57-be6a-db443e59e22c CRITICAL 9.1 The WordPress Upload Files Anywhere plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fi… — wordfence
b90640d2-d6f4-4c3b-8e9b-038d57f5fd6f
< 4.5.4
CRITICAL 9.1 The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows un… — wordfence
b8034a3b-9a25-479d-b0d8-30ed4fd76333
< 7.2.5
CRITICAL 9.1 The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to arbitrary fi… — wordfence
b7bbeeea-3888-42a6-8d14-f5c39f5dcb70
< 5.121.0
CRITICAL 9.1 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, a… — wordfence
b6b0bb48-eb61-4236-a03f-19d5d2084a75 CRITICAL 9.1 The Honeypot for WP Comment plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includi… — wordfence
b59b5c41-6173-485e-869d-4165dc18e2bd
< 22.6
CRITICAL 9.1 The Frontend File Manager Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and in… — wordfence
b50f98ca-6a51-4de8-9e89-004532ba8f96 CRITICAL 9.1 The Colormix Theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all vers… — wordfence
b3da58a5-3b07-4c53-ae20-35b3d7750023
< 1.3.3.3
CRITICAL 9.1 The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in … — wordfence
b2ef0410-3f8d-40e1-9188-43ec4e7077cd CRITICAL 9.1 The Disable Comments | WPZest plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.51… — wordfence
ae000d8a-802d-440e-9fbf-8c3b0a4a7f02
< 9.2.07.002
CRITICAL 9.1 The Photo Album Plus plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 9.2… — wordfence
acb239c2-a105-4430-8451-a6ae852a690f
< 3.3.9
CRITICAL 9.1 The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Expo… — wordfence
ac37afa3-c841-44b5-9722-952c4258841d CRITICAL 9.1 The KKProgressbar2 Free – advanced progress bars plugin for WordPress is vulnerable to SQL Injection in all versions u… — wordfence
abdca93e-f68d-4a96-8bd7-443ee46ccb5a
< 1.9.0
CRITICAL 9.1 The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat… — wordfence
aa66da82-8733-41cb-a276-620577d79e44
< 2.0.4
CRITICAL 9.1 The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.3… — wordfence
a9f5eab2-09d9-4d8e-8024-abf02b0f6b86
< 1.1.6
CRITICAL 9.1 The Movie Booking plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… — wordfence
a8447fa0-f994-4de3-b6e7-2fe61e06bed1
< 3.3.2
CRITICAL 9.1 The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determi… — wordfence
a555da8f-586a-4fb8-9230-9238df73cba4
< 1.1.14
CRITICAL 9.1 The Music Store – WordPress eCommerce plugin for WordPress is vulnerable to SQL Injection in all versions up to, and i… — wordfence
a2248ba8-b7d7-4691-bf7c-8b23c24417f7
< 3.2
CRITICAL 9.1 The WP Custom Cursors | WordPress Cursor Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_row' p… — wordfence
a147956c-a4d8-4945-997a-9b7cea60f926
< 11.2.0
CRITICAL 9.1 The PitchPrint plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in… — wordfence
a125bbf1-8ff6-4f3d-a4fb-caaaefe1df2a
< 1.7.14
CRITICAL 9.1 The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and … — wordfence
9e20afee-9336-458e-ab5c-b320c6887b83 CRITICAL 9.1 The 10Web Map Builder for Google Maps plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… — wordfence
9cb7bc91-b2e9-4ede-80cf-6b961ac6dcb9
< 0.3.0
CRITICAL 9.1 An issue was discovered in WPGraphQL up to 0.2.3 . By querying the 'users' RootQuery, it is possible, for an unauthentic… — wordfence
← Prev 104 105 106 107 108 109 110 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top