πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 109 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7eada9b7-8d53-4e95-858e-aa706f74b2a1
< 6.1.10
CRITICAL 9.1 The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 6.1… — wordfence
7c387a20-47dd-42d9-bf22-a28c613c5bde
< 2.2.0
CRITICAL 9.1 The Comic Book Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2… — wordfence
7c28869c-c880-4322-9f17-09495a08576e
< 1.57.3
CRITICAL 9.1 The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbi… — wordfence
78072f78-1c87-4ce0-b712-e10a25096316
< 4.0.2
CRITICAL 9.1 The Media folder Addon plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4… — wordfence
77db9906-ff6f-400c-bb02-8c64eb016a77
< 2.2
CRITICAL 9.1 The Method Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.1. This is d… — wordfence
7612b680-fb4a-4c5a-aa46-fb3473da78b4
< 3.2.4
CRITICAL 9.1 The Count Per Day plugin for WordPress is vulnerable to Path Disclosure and Denial of Service in versions up to, and inc… — wordfence
74dfa62b-846e-4e61-89ec-8b64d175f53a
< 1.1.8
CRITICAL 9.1 The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in … — wordfence
746ed5d5-983f-40b1-b12b-f7cbe231597c
< 1.7.12
CRITICAL 9.1 The Workscout Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio… — wordfence
74403688-06a0-453f-ac44-bd731c389892
< 2.7.2
CRITICAL 9.1 The JS Help Desk plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unkn… — wordfence
73efd9ad-9515-4ca8-bfb3-1d478f39c2b9
< 3.2.3
CRITICAL 9.1 The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuffi… — wordfence
73b78d92-5a91-4db7-ab8b-0867e4464516 CRITICAL 9.1 The Database Toolset plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat… — wordfence
738eb021-1166-4fbe-a502-2db12c6533c3
< 1.4.11
CRITICAL 9.1 The OSS Aliyun plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.10 due to insuf… — wordfence
71aa14b8-39bc-4b91-a7cf-9d203fdf44ea
< 1.7
CRITICAL 9.1 The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing … — wordfence
7167a731-8677-4ae2-a790-00a8295c9191
< 6.1.5
CRITICAL 9.1 The Fancy Product Designer plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.1… — wordfence
70a14d11-6525-465c-8fc6-0920af748027
< 1.4.1
CRITICAL 9.1 The Squeeze plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all vers… — wordfence
6c8720bc-7431-416a-8da3-62c49e2f2afd
< 3.1.0
CRITICAL 9.1 The BuddyPress XProfile Custom Image Field plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic… — wordfence
6c01f098-5fd6-4c4b-9744-c902108ed72a
< 3.1.3
CRITICAL 9.1 The WP-BusinessDirectory – Business directory plugin for WordPress plugin for WordPress is vulnerable to arbitrary fil… — wordfence
6b839c7d-76fb-465e-9f27-1882cf0099fa
< 2.12.0
CRITICAL 9.1 The WooCommerce Chained Products plugin for WordPress is vulnerable to authorization bypass due to a missing capability … — wordfence
6b3a0ceb-f42b-42dd-9308-cd66122ebb7f
< 2.1.0
CRITICAL 9.1 The Plug your WooCommerce into the largest catalog of customized print products from Helloprint plugin for WordPress is … — wordfence
6a061553-c988-4a31-a0a2-7a2608faa33f
< 1.3.5
CRITICAL 9.1 The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options… — wordfence
682a7439-d10a-48b7-84c5-60ac00cf7879
< 3.0.6
CRITICAL 9.1 The Paid Memberships Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.5 due… — wordfence
66af88ab-716f-43c9-8c05-148c3f14f676 CRITICAL 9.1 The PT Luxa Addons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio… — wordfence
654b28a2-36e7-4226-abda-5c666e54c2de CRITICAL 9.1 The E-xact | Hosted Payment | plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pat… — wordfence
63922c28-0cb5-4abe-85ee-20b2cc6f015d
< 0.0.9
CRITICAL 9.1 The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory… — wordfence
6215fa9f-06bc-4dc8-b1f5-a3bb75749f1d
< 4.9.9.1
CRITICAL 9.1 The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a… — wordfence
← Prev 106 107 108 109 110 111 112 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top