ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 109 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2019-11043 KEV CRITICAL 9.0 In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocat… cisa_kev
CVE-2019-1003030 KEV CRITICAL 9.0 Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity … cisa_kev
CVE-2019-1003029 KEV CRITICAL 9.0 Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox. cisa_kev
CVE-2019-0211 KEV CRITICAL 9.0 Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (inc… cisa_kev
CVE-2019-0193 KEV CRITICAL 9.0 The optional Apache Solr module DataImportHandler contains a code injection vulnerability. cisa_kev
CVE-2018-7602 KEV CRITICAL 9.0 A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit mu… cisa_kev
CVE-2018-7600 KEV CRITICAL 9.0 Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vecto… cisa_kev
CVE-2018-20062 KEV CRITICAL 9.0 ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of th… cisa_kev
CVE-2018-11776 KEV CRITICAL 9.0 Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alw… cisa_kev
CVE-2017-9841 KEV CRITICAL 9.0 PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as… cisa_kev
CVE-2017-9805 KEV CRITICAL 9.0 Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filter… cisa_kev
CVE-2017-9791 KEV CRITICAL 9.0 The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw messa… cisa_kev
CVE-2017-5638 KEV CRITICAL 9.0 Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote … cisa_kev
CVE-2017-12617 KEV CRITICAL 9.0 When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP … cisa_kev
CVE-2017-12615 KEV CRITICAL 9.0 When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a sp… cisa_kev
CVE-2016-8735 KEV CRITICAL 9.0 Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener … cisa_kev
CVE-2016-4437 KEV CRITICAL 9.0 Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restric… cisa_kev
CVE-2016-3088 KEV CRITICAL 9.0 The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an H… cisa_kev
CVE-2016-10033 KEV CRITICAL 9.0 PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, thi… cisa_kev
CVE-2013-2251 KEV CRITICAL 9.0 Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions. cisa_kev
CVE-2012-1823 KEV CRITICAL 9.0 sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote… cisa_kev
CVE-2012-0391 KEV CRITICAL 9.0 The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability t… cisa_kev
CVE-2009-1151 KEV CRITICAL 9.0 Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in … cisa_kev
CVE-2006-1547 KEV CRITICAL 9.0 ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-… cisa_kev
c9d5c661-bc81-4706-b930-6e3309f3d705
< 2.9.14
CRITICAL 9.0 The Affiliates Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.13. Thi… wordfence
← Prev 106 107 108 109 110 111 112 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top