πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 12 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f41a3141-e232-40f2-b800-e089a19c52fa CRITICAL 9.8 The BodyCenter - Gym, Fitness WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in v… wordfence
f3fe07df-3589-4767-a81d-a6b72c5ab1a8
< 4.2.0
CRITICAL 9.8 The LearnPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.7.3.2 vi… wordfence
f3eb1cb5-71ca-44c5-9434-e86301543357
< 3.3.4
CRITICAL 9.8 The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, departmen… wordfence
f3e618cf-dd77-45a7-ab57-5732fd329883 CRITICAL 9.8 The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user re… wordfence
f3bddb69-9c63-49e8-9c04-08361423b1c3
< 3.5
CRITICAL 9.8 SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica… wordfence
f3b727ba-b39c-4a98-a6a6-ea33785079f6
< 2.7.6
CRITICAL 9.8 The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ… wordfence
f374b3d1-820b-473f-8d2b-c3267e6d23d9
< 5.1.7
CRITICAL 9.8 The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. Thi… wordfence
f33e8906-c607-40de-8c2a-93ca12519da5
< 1.11.4
CRITICAL 9.8 The OAuth 2.0 client for SSO plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… wordfence
f33d080c-6d64-46d1-b01c-ef859106159f
< 2.0.1
CRITICAL 9.8 The Themesflat Addons For Elementor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and in… wordfence
f2ed5e51-8783-4b7f-9177-c116bf0fad44
< 3.8
CRITICAL 9.8 The Frontend File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
f2c6a377-216f-4d61-8fae-ec5bc2793cdf
< 1.6.21
CRITICAL 9.8 The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… wordfence
f28dc553-32de-459e-a0e9-2fd428ef42a0 CRITICAL 9.8 The Magnitudo theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ph… wordfence
f27bf9d3-f517-4739-914d-fe3ed13331e0
< 3.8.9
CRITICAL 9.8 The Support Board plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 3.8.9 (exclusive). Th… wordfence
f271c2e7-9d58-4dea-95d3-3ffc4ec7c3b2
< 2.3
CRITICAL 9.8 The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… wordfence
f24e711b-0b16-4948-97c9-807703a9baaf
< 1.3.2
CRITICAL 9.8 The WordPress SMTP Service, Email Delivery Solved! β€” MailHawk plugin for WordPress is vulnerable to Local File Inclusi… wordfence
f24af4f2-bb05-4833-a2bc-771143970e00
< 1.8
CRITICAL 9.8 The HD FLV Player plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… wordfence
f2488eb7-5c80-48d5-8f39-736883207937 CRITICAL 9.8 The Directorist Social Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… wordfence
f20ee38e-6af0-48d7-8ac9-2972f3c4c679 CRITICAL 9.8 The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to … wordfence
f203f30c-998b-4719-9268-0a78e1dc84be CRITICAL 9.8 The Asset Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ve… wordfence
f1d26326-c5c5-4993-aadf-298759eb873d CRITICAL 9.8 A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in … wordfence
f1c5ce2b-9ac4-4fd2-9e49-ccb8538ba100 CRITICAL 9.8 Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable bef… wordfence
f1b6fe67-cbd8-438f-8e06-d0f25eddc81a
< 0.9.8.9
CRITICAL 9.8 The Custom Content Type Manager plugin for WordPress was injected with a malicious backdoor in versions 0.9.8.7 to 0.9.8… wordfence
f188c032-6f36-45a9-9ca8-39bfe91c97d4 CRITICAL 9.8 The Konzept theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'uplo… wordfence
f17c4748-2a95-495c-ad3b-86b272855791
< 1.7.0
CRITICAL 9.8 The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via th… wordfence
f15f85c6-0bba-4bbd-b097-d205b9e0a075
< 1.0.19
CRITICAL 9.8 The Build App Online plugin for WordPress is vulnerable to SQL Injection via an AJAX action available to unprivileged us… wordfence
← Prev 9 10 11 12 13 14 15 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top