πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 11 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f804f31b-4778-4d2d-bcaa-a9f79f6753ee
< 2.5
CRITICAL 9.8 The RT-Theme 18 | Extensions plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… — wordfence
f8035ed9-d267-44da-9de4-cf3d6ece7059
< 5.1.3
CRITICAL 9.8 The WP Database Backup plugin for WordPress is vulnerable to unauthenticated settings update that can lead to remote cod… — wordfence
f775a263-1817-4da9-8fda-40f3a863a012 CRITICAL 9.8 The PegaPoll plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalati… — wordfence
f71f2096-e4c9-406a-a4e5-0006b380fbaa
< 1.9.1
CRITICAL 9.8 The VaultPress plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.9 via the… — wordfence
f6f7bff6-3bc3-4572-97fd-a039d54ac0ff
< 1.6.27
CRITICAL 9.8 The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to privilege escalation in all versions u… — wordfence
f6f3f82e-6b1b-4138-b8f3-82e8dcd24479
< 2.3.2
CRITICAL 9.8 The Phlox Portfolio plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.3… — wordfence
f6e4c583-c0d5-4040-86d5-0f1b4dddcb81
< 4.29.5
CRITICAL 9.8 Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin befo… — wordfence
f6aead8d-c136-4952-ad03-86fe0f144dea
< 0.1.0.23
CRITICAL 9.8 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due … — wordfence
f691ef0e-4649-4b06-860e-8e07375a9284 CRITICAL 9.8 The Smart Sections Theme Builder - WPBakery Page Builder Addon plugin for WordPress is vulnerable to PHP Object Injectio… — wordfence
f661f19d-fdd4-4cd3-8fb3-8b6073d94596
< 1.3.6
CRITICAL 9.8 The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… — wordfence
f655704d-70a1-40d8-ae36-39029185d262
< 10.6.7
CRITICAL 9.8 The RSVPMarker plugin for WordPress is vulnerable to SQL Injection via the 'email' parameter in versions up to, and inc… — wordfence
f5eb066b-8ab4-47e7-b055-4a9d7a897a3c
< 1.0.24
CRITICAL 9.8 The Booking Calendar Contact Form plugin for WordPress is vulnerable to blind SQL Injection via the β€˜id’ parameter i… — wordfence
f5b28fc2-4551-46dc-baa4-29ff19a1bf77
< 6.1.2
CRITICAL 9.8 The Social Discussions plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 6.1… — wordfence
f5ab09ee-53d2-4d99-824b-6a7a006bb2c2 CRITICAL 9.8 The Streamit theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.5.0. Thi… — wordfence
f59891c7-db1a-4688-8616-8877d7d7960d
< 6.6.4.1
CRITICAL 9.8 The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_… — wordfence
f58d5464-b12d-4d01-985a-68854b0b2fdd
< 1.29.0
CRITICAL 9.8 The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file… — wordfence
f53f35c4-6825-448f-a101-1439fdd63cfe
< 4.16.18
CRITICAL 9.8 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… — wordfence
f52a9da3-f8bb-4e52-9b4c-b8e5bbf077cb CRITICAL 9.8 The SV100 Companion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0… — wordfence
f51f66d7-ba47-4b7b-9b94-ea4459cf6233
< 2.3.4
CRITICAL 9.8 The JobSearch WP Job Board plugin for WordPress is vulnerable to authenticated bypass in all versions up to, and includi… — wordfence
f4ff4114-c1ed-47df-9e7c-f34f1a422ffe
< 2.9.2
CRITICAL 9.8 The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9… — wordfence
f4ea6044-bf7b-469d-89ec-a9b89ef5715e
< 3.05.1
CRITICAL 9.8 The Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin fo… — wordfence
f4bffbe6-8317-495b-b349-632c9a4f1f88 CRITICAL 9.8 The Azz Anonim Posting plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … — wordfence
f49fba00-c576-4a1a-8b0b-9ebed3e3d090
< 4.6.14
CRITICAL 9.8 The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 … — wordfence
f4893d9c-e039-43df-80b9-dbe42374caed
< 1.2.17
CRITICAL 9.8 The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.16… — wordfence
f44b9e6d-2f84-45f6-9f74-3f23b03c5a49
< 0.0.16
CRITICAL 9.8 The Password Reset with Code for WordPress REST API is vulnerable to a Weak Password Recovery Mechanism in versions up t… — wordfence
← Prev 8 9 10 11 12 13 14 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top