ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 15 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ec7f3e0c-a07c-4082-9b6b-12d0fbe0fdc8
< 1.5.3
CRITICAL 9.8 The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.… wordfence
ec547a1f-d57b-4792-b9d0-38e9a9c4d0a2
< 3.7.1.6
CRITICAL 9.8 The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPr… wordfence
ec4c14ec-d085-42c8-9e98-4155f7fa8c10 CRITICAL 9.8 The moveto plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.2. This mak… wordfence
ec3dd825-bee3-4d09-bc98-aff665988641
< 3.5.2
CRITICAL 9.8 The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from t… wordfence
ec2eec5a-7767-4215-b77d-5cfd2d148f73
< 2.3.9
CRITICAL 9.8 The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQ… wordfence
ec0d80f7-96fb-466d-9701-9751f71b926d
< 1.0.6
CRITICAL 9.8 The News Element Elementor Blog Magazine plugin for WordPress is vulnerable to Local File Inclusion in all versions up t… wordfence
ebb80964-761b-410c-998f-4408439e0d48
< 1.2.2
CRITICAL 9.8 The Patreon WordPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.2… wordfence
ebb0e616-9a57-4a77-a9ac-a938eb9b26b8 CRITICAL 9.8 The Jarvis – Night Club, Concert, Festival WordPress theme for WordPress is vulnerable to PHP Object Injection in vers… wordfence
ebacd411-6def-4026-a619-5e08a181507b
< 3.8.1
CRITICAL 9.8 The Custom 404 Pro plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in versions up to, and incl… wordfence
eb629dfc-1be2-4a56-907f-0b5c64cc066e
< 0.20
CRITICAL 9.8 PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allow… wordfence
eb58dd93-3789-46c6-bfca-7866427e077d
< 3.5.3
CRITICAL 9.8 The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi… wordfence
eb271cc8-01ec-45eb-9d6f-efc55c7c3923
< 2.5.3
CRITICAL 9.8 The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali… wordfence
eb1dca2f-5196-4f68-9c22-e8f4b3c99742 CRITICAL 9.8 The Ace User Management plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions … wordfence
eada519e-a647-4425-9e41-b8527b592c8a CRITICAL 9.8 The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress all… wordfence
ea9ee672-76d3-4d6a-b309-cd0023ca6c0d CRITICAL 9.8 The Daily Deal theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the /… wordfence
ea9e5e5d-a7fc-4159-a2ae-610bee76f818 CRITICAL 9.8 The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inclu… wordfence
ea5f9fba-6b25-40c8-b237-361eb6365693 CRITICAL 9.8 The JiangQie Free Mini Program plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… wordfence
ea4c0ad7-c7c0-49fd-85e4-612423e3ddb5 CRITICAL 9.8 The Grand Conference plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.2 vi… wordfence
ea40d06e-672c-42db-9378-d382de5838d4
< 2.4
CRITICAL 9.8 The File Manager Advanced Shortcode WordPress plugin for WordPress is vulnerable to remote code execution in versions up… wordfence
ea3ba0f5-6bc2-455c-b4e3-891ed6b2518c
< 1.4.3
CRITICAL 9.8 Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-cont… wordfence
ea00bcc9-6f9c-4704-8337-074d5356e9e2
< 4.1.5
CRITICAL 9.8 The WP Activity Log plugin for WordPress is vulnerable to SQL Injection via multiple parameters in versions up to, and i… wordfence
e9fac523-ceac-4ba2-9fcd-695afcd74308 CRITICAL 9.8 The Modal Survey plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.2.0.1.… wordfence
e9ec79e5-9f02-4a73-9437-58821ca855ef
< 2.3.2
CRITICAL 9.8 Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to b… wordfence
e9c81117-a9da-41bb-afc6-94196167af04
< 2.2.7
CRITICAL 9.8 The Social Share Buttons by Supsystic plugin for WordPress is vulnerable to SQL Injection via the ‘value’ parameter … wordfence
e9c7fb16-efbb-41e9-be13-98e96c1e9100
< 6.3.314
CRITICAL 9.8 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions… wordfence
← Prev 12 13 14 15 16 17 18 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top