πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 107 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
02b24735-0310-4b00-9acc-a05557238697 CRITICAL 9.1 The Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … wordfence
0298f5e6-36b6-4005-b6ef-d38f2f86f0b1 CRITICAL 9.1 The ENL Newsletter plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and… wordfence
0227cc13-8f19-43a2-95a1-f6e729baf256
< 1.4.3
CRITICAL 9.1 The WP Pipes plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation via … wordfence
021bd566-1663-46ba-a616-ab554b691cbb
< 4.3.3
CRITICAL 9.1 The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the… wordfence
00bcfd8f-9785-449a-a0ea-16e2583d684a
< 6.4.0.2
CRITICAL 9.1 The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6… wordfence
e32a2644-df8a-4aea-8e70-49ab3075be9e
< 1.5.4
CRITICAL 9.0 PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ… wordfence
d7e81331-0b39-4490-8624-38078b3d5420
< 4.23.56
CRITICAL 9.0 The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Remote Code Execution in all ve… wordfence
d1e5131a-9e72-441d-971c-8b9af35cf3f7
< 4.5
CRITICAL 9.0 The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPre… wordfence
CVE-2026-9082 KEV CRITICAL 9.0 Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution v… cisa_kev
CVE-2026-63030 KEV CRITICAL 9.0 WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection a… cisa_kev
CVE-2026-60137 KEV CRITICAL 9.0 WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. Th… cisa_kev
CVE-2026-56290 KEV CRITICAL 9.0 Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via u… cisa_kev
CVE-2026-54420 KEV CRITICAL 9.0 LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP… cisa_kev
CVE-2026-48907 KEV CRITICAL 9.0 Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and … cisa_kev
CVE-2026-48172 KEV CRITICAL 9.0 LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, whic… cisa_kev
CVE-2026-41940 KEV CRITICAL 9.0 WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the… cisa_kev
CVE-2026-34486 KEV CRITICAL 9.0 Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterce… cisa_kev
CVE-2026-34197 KEV CRITICAL 9.0 Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. cisa_kev
CVE-2025-24813 KEV CRITICAL 9.0 Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose informat… cisa_kev
CVE-2024-4577 KEV CRITICAL 9.0 PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arb… cisa_kev
CVE-2024-45195 KEV CRITICAL 9.0 Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access. cisa_kev
CVE-2024-38856 KEV CRITICAL 9.0 Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy paylo… cisa_kev
CVE-2024-38475 KEV CRITICAL 9.0 Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map U… cisa_kev
CVE-2024-32113 KEV CRITICAL 9.0 Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution. cisa_kev
CVE-2024-27348 KEV CRITICAL 9.0 Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute … cisa_kev
← Prev 104 105 106 107 108 109 110 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top