ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 108 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2023-46604 KEV CRITICAL 9.0 Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network… cisa_kev
CVE-2023-33246 KEV CRITICAL 9.0 Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lac… cisa_kev
CVE-2023-27524 KEV CRITICAL 9.0 Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authe… cisa_kev
CVE-2023-23752 KEV CRITICAL 9.0 Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints. cisa_kev
CVE-2022-33891 KEV CRITICAL 9.0 Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) a… cisa_kev
CVE-2022-24706 KEV CRITICAL 9.0 Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to esca… cisa_kev
CVE-2022-24112 KEV CRITICAL 9.0 Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution. cisa_kev
CVE-2021-45046 KEV CRITICAL 9.0 Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, wh… cisa_kev
CVE-2021-44228 KEV CRITICAL 9.0 Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpo… cisa_kev
CVE-2021-42013 KEV CRITICAL 9.0 Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if f… cisa_kev
CVE-2021-41773 KEV CRITICAL 9.0 Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if f… cisa_kev
CVE-2021-40438 KEV CRITICAL 9.0 A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. Th… cisa_kev
CVE-2020-25213 KEV CRITICAL 9.0 WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execut… cisa_kev
CVE-2020-1956 KEV CRITICAL 9.0 Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execut… cisa_kev
CVE-2020-1938 KEV CRITICAL 9.0 Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP co… cisa_kev
CVE-2020-17530 KEV CRITICAL 9.0 Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attr… cisa_kev
CVE-2020-17519 KEV CRITICAL 9.0 Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local fil… cisa_kev
CVE-2020-13927 KEV CRITICAL 9.0 The previous default setting for Airflow's Experimental API was to allow all API requests without authentication. cisa_kev
CVE-2020-13671 KEV CRITICAL 9.0 Improper sanitization in the extension file names is present in Drupal core. cisa_kev
CVE-2020-11978 KEV CRITICAL 9.0 A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow. cisa_kev
CVE-2020-11738 KEV CRITICAL 9.0 WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy o… cisa_kev
CVE-2019-9978 KEV CRITICAL 9.0 WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code executio… cisa_kev
CVE-2019-9082 KEV CRITICAL 9.0 ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/inv… cisa_kev
CVE-2019-6340 KEV CRITICAL 9.0 In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP cod… cisa_kev
CVE-2019-17558 KEV CRITICAL 9.0 The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code exe… cisa_kev
← Prev 105 106 107 108 109 110 111 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top