πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 13 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f1c5ce2b-9ac4-4fd2-9e49-ccb8538ba100 CRITICAL 9.8 Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable bef… — wordfence
f1b6fe67-cbd8-438f-8e06-d0f25eddc81a
< 0.9.8.9
CRITICAL 9.8 The Custom Content Type Manager plugin for WordPress was injected with a malicious backdoor in versions 0.9.8.7 to 0.9.8… — wordfence
f188c032-6f36-45a9-9ca8-39bfe91c97d4 CRITICAL 9.8 The Konzept theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'uplo… — wordfence
f17d3e43-29c6-4c80-912d-53ceda3fcb5d
< 4.8.7
CRITICAL 9.8 The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vul… — wordfence
f17c4748-2a95-495c-ad3b-86b272855791
< 1.7.0
CRITICAL 9.8 The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via th… — wordfence
f1637a3b-7b0f-485d-9d19-4f711f8c671b
< 3.29.13
CRITICAL 9.8 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all … — wordfence
f15f85c6-0bba-4bbd-b097-d205b9e0a075
< 1.0.19
CRITICAL 9.8 The Build App Online plugin for WordPress is vulnerable to SQL Injection via an AJAX action available to unprivileged us… — wordfence
f15dbce4-2e94-4735-b62b-e32d923c51ce
< 1.3
CRITICAL 9.8 The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, … — wordfence
f1388322-d935-4101-a6c4-a7c99228ddec
< 3.1.3
CRITICAL 9.8 The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via… — wordfence
f10fd160-70cc-4f27-8175-830ccb90bf63 CRITICAL 9.8 The VRPConnector plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.1 via … — wordfence
f10e5eef-1ccf-4f98-b0e9-5ed05b3881a6
< 3.1.24
CRITICAL 9.8 The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the id, and form_id param… — wordfence
f107a2be-e75b-43f3-8d41-b68c50c27f55 CRITICAL 9.8 The jQuery HTML5 File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… — wordfence
f0ec70a0-d1be-4652-b029-d8268c2667ec
< 2.8.2
CRITICAL 9.8 The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL state… — wordfence
f0ea7279-bba3-49c4-b36a-0d51c96a23cf
< 3.0
CRITICAL 9.8 importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers … — wordfence
f0e77557-f377-4752-bc5b-ec00f2520150 CRITICAL 9.8 The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Remote File Inclusion in all versions d… — wordfence
f0d3f7cb-4974-4b0f-9658-1895e5966276
< 1.2.7
CRITICAL 9.8 The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This … — wordfence
f0cb666b-bfab-492f-a74e-11dc9b171136
< 2.2.2
CRITICAL 9.8 The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab… — wordfence
f0accbee-8ab3-4e6a-b7c8-a204d681d8cf
< 4.0.1
CRITICAL 9.8 Social Media Widget (social-media-widget) plugin 4.0 for WordPress contains an externally introduced modification (Troja… — wordfence
f0a261e9-8b96-4065-8fd3-7be53cc3c9a2
< 1.0.73
CRITICAL 9.8 The 10Web Map Builder for Google Maps plugin for WordPress is vulnerable to SQL Injection via the 'radius', 'lat', and '… — wordfence
f09aed55-bfe4-4199-9cf2-73cc9bfd678c CRITICAL 9.8 The Butcher theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.40. This makes… — wordfence
f091d9fa-4331-4a21-8868-e9400472524b CRITICAL 9.8 The Ads Pro Plugin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.89. Th… — wordfence
f078b367-3ee2-4d4b-a289-eead8af511a7 CRITICAL 9.8 The Piotnet Addons For Elementor Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… — wordfence
f056aee7-8e73-41b5-8dbc-aef6557c52ab
< 1.1.3
CRITICAL 9.8 The wastia theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… — wordfence
f04eab14-dd86-4145-b5eb-20d064bc8417
< 3.6.1
CRITICAL 9.8 The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up … — wordfence
f016fcdc-02d1-46be-98b1-eaceb34c4ca1 CRITICAL 9.8 The Altair theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.2.2 via deseria… — wordfence
← Prev 10 11 12 13 14 15 16 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top