πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 12 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f4494a0f-57fb-4ed7-8fdc-85b5dcee6549
< 3.1.3
CRITICAL 9.8 The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF c… — wordfence
f441477e-35b8-42ae-b71c-3fdba126021b
< 1.2.4
CRITICAL 9.8 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via i… — wordfence
f4393526-6357-40ee-a024-f461d0430a62
< 2.0.6
CRITICAL 9.8 WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query,… — wordfence
f41eecf8-dad9-4f98-91f5-c6ac472b8810 CRITICAL 9.8 The Email Newsletter plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 20.15… — wordfence
f41a3141-e232-40f2-b800-e089a19c52fa CRITICAL 9.8 The BodyCenter - Gym, Fitness WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in v… — wordfence
f3fe07df-3589-4767-a81d-a6b72c5ab1a8
< 4.2.0
CRITICAL 9.8 The LearnPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.7.3.2 vi… — wordfence
f3eb1cb5-71ca-44c5-9434-e86301543357
< 3.3.4
CRITICAL 9.8 The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, departmen… — wordfence
f3e618cf-dd77-45a7-ab57-5732fd329883 CRITICAL 9.8 The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user re… — wordfence
f3bddb69-9c63-49e8-9c04-08361423b1c3
< 3.5
CRITICAL 9.8 SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica… — wordfence
f3b727ba-b39c-4a98-a6a6-ea33785079f6
< 2.7.6
CRITICAL 9.8 The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ… — wordfence
f39d1f86-17d7-4b22-ba42-e88e96111bd6
< 1.7.1
CRITICAL 9.8 The Firebase Authentication plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 1.7.1 (excl… — wordfence
f374b3d1-820b-473f-8d2b-c3267e6d23d9
< 5.1.7
CRITICAL 9.8 The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. Thi… — wordfence
f33e8906-c607-40de-8c2a-93ca12519da5
< 1.11.4
CRITICAL 9.8 The OAuth 2.0 client for SSO plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… — wordfence
f33d080c-6d64-46d1-b01c-ef859106159f
< 2.0.1
CRITICAL 9.8 The Themesflat Addons For Elementor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and in… — wordfence
f2ed5e51-8783-4b7f-9177-c116bf0fad44
< 3.8
CRITICAL 9.8 The Frontend File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… — wordfence
f2c6a377-216f-4d61-8fae-ec5bc2793cdf
< 1.6.21
CRITICAL 9.8 The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… — wordfence
f28dc553-32de-459e-a0e9-2fd428ef42a0 CRITICAL 9.8 The Magnitudo theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ph… — wordfence
f27bf9d3-f517-4739-914d-fe3ed13331e0
< 3.8.9
CRITICAL 9.8 The Support Board plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 3.8.9 (exclusive). Th… — wordfence
f271c2e7-9d58-4dea-95d3-3ffc4ec7c3b2
< 2.3
CRITICAL 9.8 The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… — wordfence
f24e711b-0b16-4948-97c9-807703a9baaf
< 1.3.2
CRITICAL 9.8 The WordPress SMTP Service, Email Delivery Solved! β€” MailHawk plugin for WordPress is vulnerable to Local File Inclusi… — wordfence
f24af4f2-bb05-4833-a2bc-771143970e00
< 1.8
CRITICAL 9.8 The HD FLV Player plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… — wordfence
f2488eb7-5c80-48d5-8f39-736883207937 CRITICAL 9.8 The Directorist Social Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… — wordfence
f20ee38e-6af0-48d7-8ac9-2972f3c4c679 CRITICAL 9.8 The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to … — wordfence
f203f30c-998b-4719-9268-0a78e1dc84be CRITICAL 9.8 The Asset Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ve… — wordfence
f1d26326-c5c5-4993-aadf-298759eb873d CRITICAL 9.8 A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in … — wordfence
← Prev 9 10 11 12 13 14 15 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top