πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 13 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f15dbce4-2e94-4735-b62b-e32d923c51ce
< 1.3
CRITICAL 9.8 The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, … wordfence
f1388322-d935-4101-a6c4-a7c99228ddec
< 3.1.3
CRITICAL 9.8 The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via… wordfence
f10fd160-70cc-4f27-8175-830ccb90bf63 CRITICAL 9.8 The VRPConnector plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.1 via … wordfence
f10e5eef-1ccf-4f98-b0e9-5ed05b3881a6
< 3.1.24
CRITICAL 9.8 The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the id, and form_id param… wordfence
f107a2be-e75b-43f3-8d41-b68c50c27f55 CRITICAL 9.8 The jQuery HTML5 File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… wordfence
f0ec70a0-d1be-4652-b029-d8268c2667ec
< 2.8.2
CRITICAL 9.8 The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL state… wordfence
f0ea7279-bba3-49c4-b36a-0d51c96a23cf
< 3.0
CRITICAL 9.8 importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers … wordfence
f0e77557-f377-4752-bc5b-ec00f2520150 CRITICAL 9.8 The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Remote File Inclusion in all versions d… wordfence
f0cb666b-bfab-492f-a74e-11dc9b171136
< 2.2.2
CRITICAL 9.8 The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab… wordfence
f0accbee-8ab3-4e6a-b7c8-a204d681d8cf
< 4.0.1
CRITICAL 9.8 Social Media Widget (social-media-widget) plugin 4.0 for WordPress contains an externally introduced modification (Troja… wordfence
f0a261e9-8b96-4065-8fd3-7be53cc3c9a2
< 1.0.73
CRITICAL 9.8 The 10Web Map Builder for Google Maps plugin for WordPress is vulnerable to SQL Injection via the 'radius', 'lat', and '… wordfence
f09aed55-bfe4-4199-9cf2-73cc9bfd678c CRITICAL 9.8 The Butcher theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.40. This makes… wordfence
f091d9fa-4331-4a21-8868-e9400472524b CRITICAL 9.8 The Ads Pro Plugin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.89. Th… wordfence
f056aee7-8e73-41b5-8dbc-aef6557c52ab
< 1.1.3
CRITICAL 9.8 The wastia theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… wordfence
f04eab14-dd86-4145-b5eb-20d064bc8417
< 3.6.1
CRITICAL 9.8 The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up … wordfence
f016fcdc-02d1-46be-98b1-eaceb34c4ca1 CRITICAL 9.8 The Altair theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.2.2 via deseria… wordfence
f00eeaef-f277-481f-9e18-bf1ced0015a0
< 3.3.1
CRITICAL 9.8 The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient in… wordfence
f00b2602-b9ab-4f4a-a19e-5c2a98c232e3
< 1.4.10
CRITICAL 9.8 SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQ… wordfence
f00761a7-fe24-49a3-b3e3-a471e05815c1
< 3.9.3
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This… wordfence
f006bb33-d017-445b-9c02-bd848c199671
< 1.1.38
CRITICAL 9.8 The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all v… wordfence
eff47e59-9a2c-424f-b138-47fcf554c06b
< 1.14
CRITICAL 9.8 The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and includi… wordfence
efbea599-3d04-42d2-9b91-6b68210d8b01
< 1.1
CRITICAL 9.8 The Appius theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload… wordfence
ef8bfb38-4f20-4f9f-bb30-a88f3be2d2d3
< 0.9.69
CRITICAL 9.8 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' pa… wordfence
ef8a43c7-f391-44fc-882c-26c1c8b5df78
< 1.4
CRITICAL 9.8 SQL injection vulnerability in wp-users.php in WordPress Users plugin 1.3 and possibly earlier for WordPress allows remo… wordfence
ef79e5a8-8bac-42b3-a064-6eea597701c9
< 1.0.37
CRITICAL 9.8 The Woodmart Core plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.36 vi… wordfence
← Prev 10 11 12 13 14 15 16 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top