πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 108 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9affd2b9-9576-435e-931d-f60816af0b91
< 1.7.21
CRITICAL 9.1 The CBX Bookmark & Favorite plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.20… — wordfence
9addaa26-46b3-4fbf-8986-0b8c8f2dd286 CRITICAL 9.1 The Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension plugin for WordPress is vulnera… — wordfence
9a5ce873-e90b-4bdc-b428-426818ff9a86
< 3.6.8
CRITICAL 9.1 The WP All Import plugin for WordPress is vulnerable to arbitrary code execution in versions up to, and including, 3.6.7… — wordfence
9a29aea7-9e22-4edb-80d9-266843a416a5
< 3.15
CRITICAL 9.1 The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any … — wordfence
98a274eb-036f-44f1-861d-1cfea0b34d7f
< 4.0.4
CRITICAL 9.1 The LearnPress Export Import plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.3… — wordfence
97416640-c076-4f5e-9119-adbca2fcc495 CRITICAL 9.1 Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05 — wordfence
9715d1b2-1d82-4f48-89c3-9a389ab31360
< 2.2.70
CRITICAL 9.1 The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ve… — wordfence
96e2ba3d-4e6d-42b8-832c-03ef4915cadb
< 2.4.2
CRITICAL 9.1 SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute… — wordfence
93d00b7e-cad1-4521-8acf-94818258a9d9
< 1.5.16
CRITICAL 9.1 The Scape - Multipurpose WordPress theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficien… — wordfence
901e85b9-0948-4a00-a29f-a726b53ba51b
< 2.35.8
CRITICAL 9.1 The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.35.7 due to… — wordfence
8ebb1072-ea05-4914-961d-0d8f20248078
< 3.5.0
CRITICAL 9.1 The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file… — wordfence
8cf1889b-c249-4bd7-ae23-2db66ca9d873 CRITICAL 9.1 The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress i… — wordfence
8b7e1da1-8e40-4119-894d-43e82e188608
< 1.8.11
CRITICAL 9.1 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici… — wordfence
8b0f58b8-46d6-4deb-bfcc-806bb635b060
< 5.3.4
CRITICAL 9.1 The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to SQL Injection in all versio… — wordfence
8aa0fffa-475e-4227-9ab1-17ca6fcce529
< 2.1.1
CRITICAL 9.1 In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) hea… — wordfence
8a24e409-8aa9-4d18-b428-b202407fdbfe CRITICAL 9.1 The PluginPass – WordPress PRO Plugin/Theme Licensing (Public Alpha) plugin for WordPress is vulnerable to arbitrary f… — wordfence
88b8a93b-f34f-4188-8153-ce36b03b6a4c
< 4.9.12
CRITICAL 9.1 The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.11 due to … — wordfence
885dd550-4c80-4e36-8dae-cb47c1500ea5 CRITICAL 9.1 The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-gui… — wordfence
8834d017-04e8-4748-9acc-3f2213fc8592 CRITICAL 9.1 The CarZone - A Complete Car Dealer HTML Wire-Frame theme for WordPress is vulnerable to arbitrary file deletion due to … — wordfence
86d5af9f-ffe9-4d22-885d-e117da7687de
< 3.4.5
CRITICAL 9.1 The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up… — wordfence
86218eaa-916b-4197-8fa4-62b527bd29a4 CRITICAL 9.1 The Anona - Pest Control WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficien… — wordfence
84ed666c-3154-4f26-beae-aba190f7a2f4
< 10.1.5
CRITICAL 9.1 The Import Spreadsheets from Microsoft Excel plugin for WordPress is vulnerable to arbitrary file uploads due to missing… — wordfence
813532fd-0613-47df-a4d0-54d6b33f37b3 CRITICAL 9.1 The Zynith SEO plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of serv… — wordfence
80303684-5e10-474b-b6be-a63327015826 CRITICAL 9.1 The Forms to Zapier, Integromat, IFTTT, Workato, Automate.io, elastic.io, Built.io, APIANT, Webhook plugin for WordPress… — wordfence
80067f73-53df-4014-b171-8435061a5cc7
< 2.7.8.5
CRITICAL 9.1 The Participants Database plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path va… — wordfence
← Prev 105 106 107 108 109 110 111 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top