🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 150 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9be6c569-4832-4b57-9123-0b2a26dac3a6 HIGH 8.8 Multiple themes for WordPress by Themify Themes are vulnerable to arbitrary file uploads due to missing file type valida… wordfence
9be6089f-a4ca-447c-b3fa-6917b1383512 HIGH 8.8 The Maan Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… wordfence
9bc3039c-8e96-42e9-a28d-d3204f3e84f7
< 3.0.4
HIGH 8.8 The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3… wordfence
9bbb3c65-f02c-4d6d-bd4e-b3232af5e21b
< 2.7.1
HIGH 8.8 The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in vers… wordfence
9bb520df-e838-4335-bd4f-97026082a204
< 4.16.19
HIGH 8.8 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
9bb22acd-ffdb-4897-a657-538969aa6f41
< 1.1.1
HIGH 8.8 The Video & Photo Gallery for Ultimate Member plugin for WordPress is vulnerable to arbitrary file uploads due to missin… wordfence
9baf0a14-600b-4c0e-9121-71c28653e530
< 1.8.17.0
HIGH 8.8 The WP Mailster plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.16.0 due to in… wordfence
9b95fe0e-4677-4667-9a84-96801b547088
< 1.7.6
HIGH 8.8 The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber role… wordfence
9b888f0c-5547-4ff7-9721-50166e3f0117
< 1.14.15
HIGH 8.8 The MultiParcels Shipping plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in versions up … wordfence
9b4eba78-29f2-4357-ab3c-7bc3c20e0e75
< 0.9.108
HIGH 8.8 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up… wordfence
9b4ea9ae-6a76-4dcb-ae3a-329bfb1ba547 HIGH 8.8 The WP-Recall plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 16.26.14. Thi… wordfence
9b4de243-d337-4f29-a766-bcafb3848d1c
< 2.2.5
HIGH 8.8 The Review Schema plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.4… wordfence
9aff7b03-4f03-434c-be87-b10ceeb4e625
< 2.12.0
HIGH 8.8 The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all ver… wordfence
9af8267f-48b1-4537-8985-6af1245ceed5
< 4.8
HIGH 8.8 The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access … wordfence
9aeeb92f-26f8-44b5-a523-abc33043efff HIGH 8.8 The multisite-post-duplicator plugin for WordPress has wp-admin/tools.php?page=mpd CSRF. wordfence
9ae8de00-ba4c-48d2-a566-13dac0bc4312
< 1.4.0
HIGH 8.8 The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… wordfence
9adc6f3e-2360-480c-9f91-f47474e66c78
< 1.1.2
HIGH 8.8 An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.… wordfence
9acdbd48-8d38-4d75-b2b1-c993e25cf92a HIGH 8.8 The Levo Slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation… wordfence
9ac6817e-5794-4ecb-ab3c-58b09a4e52c0 HIGH 8.8 The Estatik Mortgage Calculator plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… wordfence
9ab28410-76c5-43cb-b87a-c99f8867167c
< 2.9.3
HIGH 8.8 The Folders plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hand… wordfence
9a9c8c4f-ce07-4fe5-a573-ece675d51441
< 1.8.9
HIGH 8.8 wordfence
9a5bbbc9-7e69-45fd-a0dd-9b4faa026f95
< 1.7.8
HIGH 8.8 The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.7. Thi… wordfence
9a4f28bb-7669-483a-b93a-276b7a10826a
< 3.8.1.2
HIGH 8.8 The JetEngine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.2. T… wordfence
9a485314-cd68-400c-b398-2f8529c6a3ab
< 2.2.33.34
HIGH 8.8 The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Inject… wordfence
9a446fe7-c97a-436e-b494-b924e6518297
< 3.19
HIGH 8.8 The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
← Prev 147 148 149 150 151 152 153 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top