πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 14 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f00eeaef-f277-481f-9e18-bf1ced0015a0
< 3.3.1
CRITICAL 9.8 The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient in… — wordfence
f00b2602-b9ab-4f4a-a19e-5c2a98c232e3
< 1.4.10
CRITICAL 9.8 SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQ… — wordfence
f00761a7-fe24-49a3-b3e3-a471e05815c1
< 3.9.3
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This… — wordfence
f006bb33-d017-445b-9c02-bd848c199671
< 1.1.38
CRITICAL 9.8 The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all v… — wordfence
eff47e59-9a2c-424f-b138-47fcf554c06b
< 1.14
CRITICAL 9.8 The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and includi… — wordfence
efbea599-3d04-42d2-9b91-6b68210d8b01
< 1.1
CRITICAL 9.8 The Appius theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload… — wordfence
ef8bfb38-4f20-4f9f-bb30-a88f3be2d2d3
< 0.9.69
CRITICAL 9.8 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' pa… — wordfence
ef8a43c7-f391-44fc-882c-26c1c8b5df78
< 1.4
CRITICAL 9.8 SQL injection vulnerability in wp-users.php in WordPress Users plugin 1.3 and possibly earlier for WordPress allows remo… — wordfence
ef79e5a8-8bac-42b3-a064-6eea597701c9
< 1.0.37
CRITICAL 9.8 The Woodmart Core plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.36 vi… — wordfence
ef566dca-91ed-4929-b36b-4e424e07e1d4
< 2.0.4
CRITICAL 9.8 The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc… — wordfence
ef104a10-9e47-420b-aba9-71095870bf4f CRITICAL 9.8 The SlimStat-Ex plugin for WordPress is vulnerable to Arbitrary Code Execution via the 'ofc_upload_image.php' file in ve… — wordfence
eef9e2fa-d8f0-42bf-95ac-ee4cafff0b14
< 1.1.1
CRITICAL 9.8 The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing f… — wordfence
eee9d564-5d52-47fa-a6a5-b908bb64a2ba CRITICAL 9.8 The Clockstone theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u… — wordfence
eec9bbc0-5a68-4624-a672-bd6227d6fa45
< 3.8
CRITICAL 9.8 The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all … — wordfence
eec34b6a-aae7-4267-accd-96ebc6b71dd3 CRITICAL 9.8 The SEO Watcher plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.3.3. Thi… — wordfence
ee95092d-6351-4612-872d-284165bc1201
< 5.4.4
CRITICAL 9.8 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Alg… — wordfence
ee8ad691-b598-4eeb-b8a7-645c3bd968ff
< 1.3
CRITICAL 9.8 The WP Business intelligence lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … — wordfence
ee755e25-5f70-4688-b08d-4a3f127d91d4
< 6.2.1
CRITICAL 9.8 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Remote Code Exec… — wordfence
ee702ee5-d1de-4b25-8c2d-f47cc4ad076b
< 1.7.1
CRITICAL 9.8 The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make … — wordfence
ee678085-ce74-4a35-9d90-3b94a3d39a8e
< 1.20.1
CRITICAL 9.8 The Ultimate Addons for Elementor plugin for WordPress is vulnerable to authorization bypass due to a missing capability… — wordfence
ee3548ca-423f-4e2f-b87b-366200b31777
< 2.3
CRITICAL 9.8 The Testimonial plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2. … — wordfence
ee08121e-68eb-4849-b102-3370a4cdae77 CRITICAL 9.8 The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to authentication bypass in all versio… — wordfence
ee045d0d-101a-4ae2-b209-4a4865eec195 CRITICAL 9.8 The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on th… — wordfence
eddb2224-d041-4f86-af76-51ae973e9b29
< 1.2.1
CRITICAL 9.8 The Vizeon - Business Consulting theme for WordPress is vulnerable to Local File Inclusion in versions up to, and exclud… — wordfence
edd1b549-0975-446d-8ff8-770dbc957f92
< 5.0.7
CRITICAL 9.8 The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise an… — wordfence
← Prev 11 12 13 14 15 16 17 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top