πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 14 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ef566dca-91ed-4929-b36b-4e424e07e1d4
< 2.0.4
CRITICAL 9.8 The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc… wordfence
ef104a10-9e47-420b-aba9-71095870bf4f CRITICAL 9.8 The SlimStat-Ex plugin for WordPress is vulnerable to Arbitrary Code Execution via the 'ofc_upload_image.php' file in ve… wordfence
eef9e2fa-d8f0-42bf-95ac-ee4cafff0b14
< 1.1.1
CRITICAL 9.8 The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing f… wordfence
eee9d564-5d52-47fa-a6a5-b908bb64a2ba CRITICAL 9.8 The Clockstone theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u… wordfence
eec9bbc0-5a68-4624-a672-bd6227d6fa45
< 3.8
CRITICAL 9.8 The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all … wordfence
eec34b6a-aae7-4267-accd-96ebc6b71dd3 CRITICAL 9.8 The SEO Watcher plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.3.3. Thi… wordfence
ee95092d-6351-4612-872d-284165bc1201
< 5.4.4
CRITICAL 9.8 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Alg… wordfence
ee8ad691-b598-4eeb-b8a7-645c3bd968ff
< 1.3
CRITICAL 9.8 The WP Business intelligence lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … wordfence
ee702ee5-d1de-4b25-8c2d-f47cc4ad076b
< 1.7.1
CRITICAL 9.8 The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make … wordfence
ee678085-ce74-4a35-9d90-3b94a3d39a8e
< 1.20.1
CRITICAL 9.8 The Ultimate Addons for Elementor plugin for WordPress is vulnerable to authorization bypass due to a missing capability… wordfence
ee3548ca-423f-4e2f-b87b-366200b31777
< 2.3
CRITICAL 9.8 The Testimonial plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2. … wordfence
ee08121e-68eb-4849-b102-3370a4cdae77 CRITICAL 9.8 The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to authentication bypass in all versio… wordfence
ee045d0d-101a-4ae2-b209-4a4865eec195 CRITICAL 9.8 The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on th… wordfence
eddb2224-d041-4f86-af76-51ae973e9b29
< 1.2.1
CRITICAL 9.8 The Vizeon - Business Consulting theme for WordPress is vulnerable to Local File Inclusion in versions up to, and exclud… wordfence
edd1b549-0975-446d-8ff8-770dbc957f92
< 5.0.7
CRITICAL 9.8 The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise an… wordfence
ed738dc5-7848-4b04-a3fd-317cc366acfa
< 5.7
CRITICAL 9.8 The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
ed4854f3-b991-4133-acb9-12d99c399c90
< 1.7.2
CRITICAL 9.8 The Wanderland theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.1. This m… wordfence
ed3ad791-4d4d-41df-bf14-2aef77d6fecb
< 1.8
CRITICAL 9.8 The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection. wordfence
ed19835f-2718-41d8-95af-47c8b9589529
< 8.5.0
CRITICAL 9.8 The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all version… wordfence
ed038d39-9389-49d3-bfdd-b97fadb8e29b CRITICAL 9.8 The Exam Matrix plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5. Th… wordfence
ecfdf7b1-9bb8-4c1d-a00a-ca1e44440cab
< 1.3.6.1
CRITICAL 9.8 The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injectio… wordfence
ecec3eb4-04db-47af-974f-bacc530a7c70 CRITICAL 9.8 The Adding drop down roles in registration plugin for WordPress is vulnerable to privilege escalation in all versions up… wordfence
ecd35d5a-5270-4132-bc62-d75da5141313
< 1.4.3
CRITICAL 9.8 The Floating Social Media Links plugin for WordPress is vulnerable to Remote File Inclusion in versions before 1.4.3 via… wordfence
ec9cd4a8-286e-43d7-8cb6-6cc363800e20
< 1.4.4
CRITICAL 9.8 The MailerLite Signup Forms plugin for WordPress is vulnerable to SQL Injection via the 'form_id' parameter in versions … wordfence
ec866ff1-cce1-4f39-b22f-2d4780cb85f0 CRITICAL 9.8 The One-Login plugin for WordPress is vulnerable to Privilege Escalation n all versions up to, and including, 1.4. This … wordfence
← Prev 11 12 13 14 15 16 17 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top