ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 17 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e5af0317-ef46-4744-9752-74ce228b5f37
< 0.9.124
CRITICAL 9.8 The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbi… wordfence
e5a26786-2b15-43ce-a992-fd8cc9cf5600
< 1.3.8
CRITICAL 9.8 SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers … wordfence
e582fa40-b03e-4194-b612-d139e981cce2
< 2.7
CRITICAL 9.8 The Display Widgets plugin for WordPress is vulnerable to a developer-created backdoor that injected SEOspam into sites … wordfence
e57f7912-4af3-4dcb-b267-afec1c373b00
< 1.1.0
CRITICAL 9.8 The Wp-ImageZoom plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in the 'zoom.php' fi… wordfence
e5539ad8-4203-4d22-9a40-0ed6e0471e19
< 2.2.2
CRITICAL 9.8 WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externa… wordfence
e5441e7e-9be1-434e-9413-31920f565184
< 1.5.0
CRITICAL 9.8 The Krowd theme for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 1.5.0. This makes … wordfence
e52b34fe-2414-4d6f-bf43-9c5b65ebf769
< 5.9.0
CRITICAL 9.8 The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all ve… wordfence
e4fdc902-4cfe-4116-a294-9a0fcb2de346
< 4.14.4
CRITICAL 9.8 The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on t… wordfence
e4d51a0c-c625-4732-b345-df02971fbffa
< 2.4.8
CRITICAL 9.8 The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. Th… wordfence
e4bede17-d174-42d0-a25e-bf7fe10e4206
< 1.2.9
CRITICAL 9.8 The Quentn WP plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.8. Th… wordfence
e49c7b2a-5241-4762-b7c9-c33b1ac4a668 CRITICAL 9.8 The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and… wordfence
e4941cce-c6c0-4e8a-859e-cf0f50f92ce6
< 2.4.15
CRITICAL 9.8 The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it i… wordfence
e47f6c33-1a4b-4c4c-8323-99d06ce0731a CRITICAL 9.8 The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Cont… wordfence
e44c5dc0-6bf6-417a-9383-b345ff57ac32
< 2.1.1
CRITICAL 9.8 The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnera… wordfence
e391f560-2037-4180-a77e-1731524a318c
< 2.0.4
CRITICAL 9.8 The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deseria… wordfence
e353a269-c7f5-4b6a-9f9e-be459ead0335
< 59.4
CRITICAL 9.8 The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions su… wordfence
e342b1c0-6e7f-4e2c-8a52-018df12c12a0
< 2.4.5
CRITICAL 9.8 The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… wordfence
e30b62de-7280-4c29-b882-dfa83e65966b
< 2.7.0
CRITICAL 9.8 The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versi… wordfence
e2b24858-dfcd-46f3-9552-c7acc63a1ee7
< 3.6.1
CRITICAL 9.8 The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the… wordfence
e28ae1a3-abc6-484c-abc7-1e0b958fa30b CRITICAL 9.8 The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, a… wordfence
e2837399-c44f-494e-bdc6-f9c6e4e2dc11
< 2.7
CRITICAL 9.8 The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to,… wordfence
e27c1d20-cef7-4801-beb9-adaeb1b95145 CRITICAL 9.8 Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membe… wordfence
e27971a3-f84c-4f13-81af-127e7560566a
< 5.2.5
CRITICAL 9.8 The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation … wordfence
e26a1c7c-8c4d-450d-bbfa-6ab1af4bceba
< 2.3.0
CRITICAL 9.8 The Tevolution Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … wordfence
e24c9e9a-4f18-41b6-a0b7-700fecb5d3e6 CRITICAL 9.8 The Sayfa Sayaç plugin for WordPress is vulnerable to SQL Injection via the in versions up to, and including, 2.6 due t… wordfence
← Prev 14 15 16 17 18 19 20 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top