🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 16 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e988d042-147c-4782-b728-71f5a50cecd8
< 5.7.2
CRITICAL 9.8 The Essential Addons for Elementor plugin for WordPress is vulnerable to Unauthenticated Arbitrary Password Resets to Pr… wordfence
e95b2bfe-8675-4932-9b37-73ad15fa228e
< 2.5.1.2
CRITICAL 9.8 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ p… wordfence
e94f9cde-5e8b-4d68-8ede-12d678a370ed
< 3.12.3
CRITICAL 9.8 The Amazon Affiliate plugin for WordPress is vulnerable to Reflected File Download via image proxy in versions up to, an… wordfence
e920caeb-5ee6-4428-9b53-edee316ee39f CRITICAL 9.8 SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote atta… wordfence
e901c2a0-2477-4b9a-8483-6002419e0a2f
< 1.26.5
CRITICAL 9.8 The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all version… wordfence
e8c01984-e8ba-4671-b63c-46ea245e7efa
< 3.5.6
CRITICAL 9.8 The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by def… wordfence
e87d7ca0-6fa3-4ca3-b308-d47e1e2e6566 CRITICAL 9.8 The Eptonic theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the VALUM… wordfence
e8574ff9-847c-4337-8c0e-2a717b51f66c
< 3.1.4
CRITICAL 9.8 The Adifier System theme for WordPress is vulnerable to Local File Inclusion in all versions up to 3.1.4 (exclusive). Th… wordfence
e8469ffc-477a-4ff1-853b-dcefba2b9c4e
< 1.2.3
CRITICAL 9.8 The Rockhoist Ratings plugin for WordPress is vulnerable to generic SQL Injection via several parameters in versions up … wordfence
e83ad1b7-e7d6-41cd-87de-c98362e31879 CRITICAL 9.8 The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authe… wordfence
e820c00d-0456-49e8-aca4-bb981a9cfea1 CRITICAL 9.8 Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-… wordfence
e8088547-650f-41b1-bb53-18be38f4aeb2
< 2.1
CRITICAL 9.8 The link-log plugin before 2.1 for WordPress has SQL injection via the ipaddress parameter. wordfence
e8021ef2-e1ce-442a-965a-b2628fe48964 CRITICAL 9.8 The Curvo Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload… wordfence
e7f3e583-a486-4e25-bc40-e437cf5b3ebd
< 3.2.1
CRITICAL 9.8 The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion via $_GET['tab'].'.php' parameter i… wordfence
e7eb6137-5c03-4f73-a478-c1c18ee91fba
< 1.6.3
CRITICAL 9.8 The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection via the 't' parameter in the 'view… wordfence
e7b78960-51ff-440f-8831-d50c11961d9d CRITICAL 9.8 The Deep Blue theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the up… wordfence
e7b56ec1-8735-4404-8069-219f5d8866d0
< 1.7.1
CRITICAL 9.8 The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo… wordfence
e7a6dee6-b3ff-4325-a356-4a65ab7a0ce5
< 2.0.3
CRITICAL 9.8 The Accordions plugin for WordPress is vulnerable to arbitrary options update in versions up to, and including, 2.0.2. T… wordfence
e770d1fc-b941-4f0f-87ee-8b0c9edb640b CRITICAL 9.8 The FL3R FeelBox plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.1 due to insuff… wordfence
e731292a-4f95-46eb-889e-b00d58f3444e
< 3.9.1
CRITICAL 9.8 The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized passwo… wordfence
e6dd0493-dd32-44a2-9a8f-e0c86385a083
< 5.37
CRITICAL 9.8 The FacturaONE para WooCommerce con VeriFactu plugin for WordPress is vulnerable to Remote Code Execution in all version… wordfence
e6d1ad58-894c-40ed-968e-9ce64eebba55
< 1.6.2
CRITICAL 9.8 The Advanced Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the ‘calendarId’ parameter in … wordfence
e6cb81e5-61a4-4b67-a668-d8a7d46b2cea
< 1.6.11
CRITICAL 9.8 The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo… wordfence
e6977a58-cce0-4ae8-abe6-1870bbb2bf06
< 1.2.0
CRITICAL 9.8 The Youzify Plugin for WordPress is vulnerable to SQL injection via the 'youzify_media_pagination' AJAX action in versio… wordfence
e675d64c-cbb8-4f24-9b6f-2597a97b49af
< 2.8.8
CRITICAL 9.8 The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress… wordfence
← Prev 13 14 15 16 17 18 19 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top