πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 11 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f6f7bff6-3bc3-4572-97fd-a039d54ac0ff
< 1.6.27
CRITICAL 9.8 The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to privilege escalation in all versions u… wordfence
f6f3f82e-6b1b-4138-b8f3-82e8dcd24479
< 2.3.2
CRITICAL 9.8 The Phlox Portfolio plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.3… wordfence
f6e4c583-c0d5-4040-86d5-0f1b4dddcb81
< 4.29.5
CRITICAL 9.8 Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin befo… wordfence
f6aead8d-c136-4952-ad03-86fe0f144dea
< 0.1.0.23
CRITICAL 9.8 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due … wordfence
f691ef0e-4649-4b06-860e-8e07375a9284 CRITICAL 9.8 The Smart Sections Theme Builder - WPBakery Page Builder Addon plugin for WordPress is vulnerable to PHP Object Injectio… wordfence
f661f19d-fdd4-4cd3-8fb3-8b6073d94596
< 1.3.6
CRITICAL 9.8 The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… wordfence
f655704d-70a1-40d8-ae36-39029185d262
< 10.6.7
CRITICAL 9.8 The RSVPMarker plugin for WordPress is vulnerable to SQL Injection via the 'email' parameter in versions up to, and inc… wordfence
f5eb066b-8ab4-47e7-b055-4a9d7a897a3c
< 1.0.24
CRITICAL 9.8 The Booking Calendar Contact Form plugin for WordPress is vulnerable to blind SQL Injection via the β€˜id’ parameter i… wordfence
f5b28fc2-4551-46dc-baa4-29ff19a1bf77
< 6.1.2
CRITICAL 9.8 The Social Discussions plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 6.1… wordfence
f5ab09ee-53d2-4d99-824b-6a7a006bb2c2 CRITICAL 9.8 The Streamit theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.5.0. Thi… wordfence
f59891c7-db1a-4688-8616-8877d7d7960d
< 6.6.4.1
CRITICAL 9.8 The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_… wordfence
f58d5464-b12d-4d01-985a-68854b0b2fdd
< 1.29.0
CRITICAL 9.8 The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file… wordfence
f53f35c4-6825-448f-a101-1439fdd63cfe
< 4.16.18
CRITICAL 9.8 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
f52a9da3-f8bb-4e52-9b4c-b8e5bbf077cb CRITICAL 9.8 The SV100 Companion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0… wordfence
f51f66d7-ba47-4b7b-9b94-ea4459cf6233
< 2.3.4
CRITICAL 9.8 The JobSearch WP Job Board plugin for WordPress is vulnerable to authenticated bypass in all versions up to, and includi… wordfence
f4ff4114-c1ed-47df-9e7c-f34f1a422ffe
< 2.9.2
CRITICAL 9.8 The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9… wordfence
f4ea6044-bf7b-469d-89ec-a9b89ef5715e
< 3.05.1
CRITICAL 9.8 The Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin fo… wordfence
f4bffbe6-8317-495b-b349-632c9a4f1f88 CRITICAL 9.8 The Azz Anonim Posting plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
f49fba00-c576-4a1a-8b0b-9ebed3e3d090
< 4.6.14
CRITICAL 9.8 The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 … wordfence
f4893d9c-e039-43df-80b9-dbe42374caed
< 1.2.17
CRITICAL 9.8 The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.16… wordfence
f44b9e6d-2f84-45f6-9f74-3f23b03c5a49
< 0.0.16
CRITICAL 9.8 The Password Reset with Code for WordPress REST API is vulnerable to a Weak Password Recovery Mechanism in versions up t… wordfence
f4494a0f-57fb-4ed7-8fdc-85b5dcee6549
< 3.1.3
CRITICAL 9.8 The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF c… wordfence
f441477e-35b8-42ae-b71c-3fdba126021b
< 1.2.4
CRITICAL 9.8 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via i… wordfence
f4393526-6357-40ee-a024-f461d0430a62
< 2.0.6
CRITICAL 9.8 WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query,… wordfence
f41eecf8-dad9-4f98-91f5-c6ac472b8810 CRITICAL 9.8 The Email Newsletter plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 20.15… wordfence
← Prev 8 9 10 11 12 13 14 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top