πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 113 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f9cee379-79f8-4a60-b1bb-ccab1e954512
< 2.6.2
HIGH 8.8 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection vi… wordfence
f9ce0ae8-4729-4236-b4e8-e5726f4d3101
< 2.8.6
HIGH 8.8 Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress befor… wordfence
f9bfa726-40e1-4417-9d59-289dbb3a17ff
< 3.7.35
HIGH 8.8 WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC. wordfence
f9b90e03-cdaa-4bd3-9afd-5d5c91a17962
< 17.0.5
HIGH 8.8 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 17.0.4 due to… wordfence
f9a2d45c-397f-4a2b-9d7f-760b7d561c2a
< 1.0.8
HIGH 8.8 SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin <=… wordfence
f98bb2a2-6525-4e0b-8bbd-968cf5b122dc HIGH 8.8 The Superior FAQ plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… wordfence
f970ce63-da48-44ad-935c-e75f9791103c HIGH 8.8 The Pet World theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.8 via deseri… wordfence
f938a446-ae0b-4e06-9d55-26e2fea4d1e8 HIGH 8.8 The Stock in & out WordPress plugin for WordPress is vulnerable to SQL Injection via the product_id parameter in version… wordfence
f90b6cdb-d929-493e-b078-4762b7e2f76d
< 1.2.36
HIGH 8.8 The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functio… wordfence
f8f92355-e664-4aeb-9094-9c8aa49cd3e7
< 22-05-2018
HIGH 8.8 Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter. wordfence
f8f31d01-7bbc-4ef8-a099-b957f3d20118
< 5.4.2
HIGH 8.8 The WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce plugin for WordPress is vulnerable … wordfence
f8ccf307-3bb8-45c5-91da-7d0f46e96694
< 3.0.5
HIGH 8.8 The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF. wordfence
f8c85f61-3e0a-4dbe-a5d6-ab01dea000a7
< 0.9.8
HIGH 8.8 The Ecommerce Zone theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in al… wordfence
f89e9c46-aca3-4b2f-b935-2976c510ed8b
< 3.5.6.9
HIGH 8.8 The 3DPrint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and excluding, 3.5.6.9. … wordfence
f89ba641-6c78-48d3-8826-96576198274f
< 3.2.1
HIGH 8.8 The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attacke… wordfence
f89718f2-e25b-4393-986a-34ef3076a59c
< 2.3.10
HIGH 8.8 The WP Google Map plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature. wordfence
f8953c5c-0711-4c29-8055-62b3a168b369
< 1.4.5
HIGH 8.8 The Logo Showcase Ultimate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … wordfence
f87e78c5-e7f4-4af6-b64f-444fef23e890
< 4.8.4
HIGH 8.8 The Slimstat Analytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
f87b6987-8896-4edf-9b14-8582426adeb0
< 1.3.2
HIGH 8.8 The My Account Page Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
f8758fd2-9f43-4e31-b496-50b77180bc07
< 2.1
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPre… wordfence
f861ece5-21e4-4c7f-8701-bd9492b1b8bf HIGH 8.8 The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path… wordfence
f8615422-5db7-495d-9956-7d6f658f42bf
< 2.1.20
HIGH 8.8 The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, a… wordfence
f8470662-2247-4159-9dac-f13677c94bdf
< 10.9.0
HIGH 8.8 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is… wordfence
f8375ecf-e64b-4649-9341-fa45bf5556c3 HIGH 8.8 The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation … wordfence
f8297149-2de3-4e49-80f9-6ea59dea6bce
< 3.0.5
HIGH 8.8 The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fet… wordfence
← Prev 110 111 112 113 114 115 116 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top