πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 15 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ed738dc5-7848-4b04-a3fd-317cc366acfa
< 5.7
CRITICAL 9.8 The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… — wordfence
ed4854f3-b991-4133-acb9-12d99c399c90
< 1.7.2
CRITICAL 9.8 The Wanderland theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.1. This m… — wordfence
ed3ad791-4d4d-41df-bf14-2aef77d6fecb
< 1.8
CRITICAL 9.8 The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection. — wordfence
ed19835f-2718-41d8-95af-47c8b9589529
< 8.5.0
CRITICAL 9.8 The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all version… — wordfence
ed038d39-9389-49d3-bfdd-b97fadb8e29b CRITICAL 9.8 The Exam Matrix plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5. Th… — wordfence
ecfdf7b1-9bb8-4c1d-a00a-ca1e44440cab
< 1.3.6.1
CRITICAL 9.8 The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injectio… — wordfence
ecec3eb4-04db-47af-974f-bacc530a7c70 CRITICAL 9.8 The Adding drop down roles in registration plugin for WordPress is vulnerable to privilege escalation in all versions up… — wordfence
ecd35d5a-5270-4132-bc62-d75da5141313
< 1.4.3
CRITICAL 9.8 The Floating Social Media Links plugin for WordPress is vulnerable to Remote File Inclusion in versions before 1.4.3 via… — wordfence
ec9cd4a8-286e-43d7-8cb6-6cc363800e20
< 1.4.4
CRITICAL 9.8 The MailerLite Signup Forms plugin for WordPress is vulnerable to SQL Injection via the 'form_id' parameter in versions … — wordfence
ec866ff1-cce1-4f39-b22f-2d4780cb85f0 CRITICAL 9.8 The One-Login plugin for WordPress is vulnerable to Privilege Escalation n all versions up to, and including, 1.4. This … — wordfence
ec8666d4-042e-4cf4-86f5-474a69d90ff6
< 2.3.23
CRITICAL 9.8 The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection … — wordfence
ec7f3e0c-a07c-4082-9b6b-12d0fbe0fdc8
< 1.5.3
CRITICAL 9.8 The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.… — wordfence
ec547a1f-d57b-4792-b9d0-38e9a9c4d0a2
< 3.7.1.6
CRITICAL 9.8 The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPr… — wordfence
ec4c14ec-d085-42c8-9e98-4155f7fa8c10 CRITICAL 9.8 The moveto plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.2. This mak… — wordfence
ec3dd825-bee3-4d09-bc98-aff665988641
< 3.5.2
CRITICAL 9.8 The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from t… — wordfence
ec2eec5a-7767-4215-b77d-5cfd2d148f73
< 2.3.9
CRITICAL 9.8 The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQ… — wordfence
ec1ce091-7aac-4ec6-8f6f-6d961e2073cb
< 2.4
CRITICAL 9.8 The wpShopGermany IT-RECHT KANZLEI plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, an… — wordfence
ec0d80f7-96fb-466d-9701-9751f71b926d
< 1.0.6
CRITICAL 9.8 The News Element Elementor Blog Magazine plugin for WordPress is vulnerable to Local File Inclusion in all versions up t… — wordfence
ebb80964-761b-410c-998f-4408439e0d48
< 1.2.2
CRITICAL 9.8 The Patreon WordPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.2… — wordfence
ebb0e616-9a57-4a77-a9ac-a938eb9b26b8 CRITICAL 9.8 The Jarvis – Night Club, Concert, Festival WordPress theme for WordPress is vulnerable to PHP Object Injection in vers… — wordfence
ebacd411-6def-4026-a619-5e08a181507b
< 3.8.1
CRITICAL 9.8 The Custom 404 Pro plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in versions up to, and incl… — wordfence
eb629dfc-1be2-4a56-907f-0b5c64cc066e
< 0.20
CRITICAL 9.8 PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allow… — wordfence
eb58dd93-3789-46c6-bfca-7866427e077d
< 3.5.3
CRITICAL 9.8 The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi… — wordfence
eb271cc8-01ec-45eb-9d6f-efc55c7c3923
< 2.5.3
CRITICAL 9.8 The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali… — wordfence
eb1dca2f-5196-4f68-9c22-e8f4b3c99742 CRITICAL 9.8 The Ace User Management plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions … — wordfence
← Prev 12 13 14 15 16 17 18 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top