🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 16 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
eb075839-5669-4a5a-b225-f7ea98672490
< 1.0.49
CRITICAL 9.8 The Newspapers X theme for WordPress contains a backdoor in versions 1.0.46 to 1.0.48. This makes it possible for unauth… — wordfence
eada519e-a647-4425-9e41-b8527b592c8a CRITICAL 9.8 The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress all… — wordfence
ea9ee672-76d3-4d6a-b309-cd0023ca6c0d CRITICAL 9.8 The Daily Deal theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the /… — wordfence
ea9e5e5d-a7fc-4159-a2ae-610bee76f818 CRITICAL 9.8 The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inclu… — wordfence
ea5f9fba-6b25-40c8-b237-361eb6365693 CRITICAL 9.8 The JiangQie Free Mini Program plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… — wordfence
ea4c0ad7-c7c0-49fd-85e4-612423e3ddb5 CRITICAL 9.8 The Grand Conference plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.2 vi… — wordfence
ea40d06e-672c-42db-9378-d382de5838d4
< 2.4
CRITICAL 9.8 The File Manager Advanced Shortcode WordPress plugin for WordPress is vulnerable to remote code execution in versions up… — wordfence
ea3ba0f5-6bc2-455c-b4e3-891ed6b2518c
< 1.4.3
CRITICAL 9.8 Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-cont… — wordfence
ea07c3c1-95e6-4139-b4f5-67ca642f0563 CRITICAL 9.8 The Developer Tools plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.… — wordfence
ea00bcc9-6f9c-4704-8337-074d5356e9e2
< 4.1.5
CRITICAL 9.8 The WP Activity Log plugin for WordPress is vulnerable to SQL Injection via multiple parameters in versions up to, and i… — wordfence
e9fac523-ceac-4ba2-9fcd-695afcd74308 CRITICAL 9.8 The Modal Survey plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.2.0.1.… — wordfence
e9ec79e5-9f02-4a73-9437-58821ca855ef
< 2.3.2
CRITICAL 9.8 Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to b… — wordfence
e9c81117-a9da-41bb-afc6-94196167af04
< 2.2.7
CRITICAL 9.8 The Social Share Buttons by Supsystic plugin for WordPress is vulnerable to SQL Injection via the ‘value’ parameter … — wordfence
e9c7fb16-efbb-41e9-be13-98e96c1e9100
< 6.3.314
CRITICAL 9.8 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions… — wordfence
e988d042-147c-4782-b728-71f5a50cecd8
< 5.7.2
CRITICAL 9.8 The Essential Addons for Elementor plugin for WordPress is vulnerable to Unauthenticated Arbitrary Password Resets to Pr… — wordfence
e95b2bfe-8675-4932-9b37-73ad15fa228e
< 2.5.1.2
CRITICAL 9.8 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ p… — wordfence
e94f9cde-5e8b-4d68-8ede-12d678a370ed
< 3.12.3
CRITICAL 9.8 The Amazon Affiliate plugin for WordPress is vulnerable to Reflected File Download via image proxy in versions up to, an… — wordfence
e93c8b3a-d8d8-4d2b-9df0-ea27e33947e0
< 4.0.2
CRITICAL 9.8 The Login & Register Customizer – Forms, Popup, Profile & WooCommerce plugin for WordPress is vulnerable to privilege … — wordfence
e920caeb-5ee6-4428-9b53-edee316ee39f CRITICAL 9.8 SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote atta… — wordfence
e901c2a0-2477-4b9a-8483-6002419e0a2f
< 1.26.5
CRITICAL 9.8 The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all version… — wordfence
e8c01984-e8ba-4671-b63c-46ea245e7efa
< 3.5.6
CRITICAL 9.8 The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by def… — wordfence
e87d7ca0-6fa3-4ca3-b308-d47e1e2e6566 CRITICAL 9.8 The Eptonic theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the VALUM… — wordfence
e8574ff9-847c-4337-8c0e-2a717b51f66c
< 3.1.4
CRITICAL 9.8 The Adifier System theme for WordPress is vulnerable to Local File Inclusion in all versions up to 3.1.4 (exclusive). Th… — wordfence
e8469ffc-477a-4ff1-853b-dcefba2b9c4e
< 1.2.3
CRITICAL 9.8 The Rockhoist Ratings plugin for WordPress is vulnerable to generic SQL Injection via several parameters in versions up … — wordfence
e83ad1b7-e7d6-41cd-87de-c98362e31879 CRITICAL 9.8 The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authe… — wordfence
← Prev 13 14 15 16 17 18 19 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top