🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 17 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e820c00d-0456-49e8-aca4-bb981a9cfea1 CRITICAL 9.8 Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-… — wordfence
e8088547-650f-41b1-bb53-18be38f4aeb2
< 2.1
CRITICAL 9.8 The link-log plugin before 2.1 for WordPress has SQL injection via the ipaddress parameter. — wordfence
e8021ef2-e1ce-442a-965a-b2628fe48964 CRITICAL 9.8 The Curvo Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload… — wordfence
e7f3e583-a486-4e25-bc40-e437cf5b3ebd
< 3.2.1
CRITICAL 9.8 The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion via $_GET['tab'].'.php' parameter i… — wordfence
e7eb6137-5c03-4f73-a478-c1c18ee91fba
< 1.6.3
CRITICAL 9.8 The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection via the 't' parameter in the 'view… — wordfence
e7b78960-51ff-440f-8831-d50c11961d9d CRITICAL 9.8 The Deep Blue theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the up… — wordfence
e7b56ec1-8735-4404-8069-219f5d8866d0
< 1.7.1
CRITICAL 9.8 The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo… — wordfence
e7a6dee6-b3ff-4325-a356-4a65ab7a0ce5
< 2.0.3
CRITICAL 9.8 The Accordions plugin for WordPress is vulnerable to arbitrary options update in versions up to, and including, 2.0.2. T… — wordfence
e770d1fc-b941-4f0f-87ee-8b0c9edb640b CRITICAL 9.8 The FL3R FeelBox plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.1 due to insuff… — wordfence
e731292a-4f95-46eb-889e-b00d58f3444e
< 3.9.1
CRITICAL 9.8 The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized passwo… — wordfence
e6dd0493-dd32-44a2-9a8f-e0c86385a083
< 5.37
CRITICAL 9.8 The FacturaONE para WooCommerce con VeriFactu plugin for WordPress is vulnerable to Remote Code Execution in all version… — wordfence
e6d1ad58-894c-40ed-968e-9ce64eebba55
< 1.6.2
CRITICAL 9.8 The Advanced Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the ‘calendarId’ parameter in … — wordfence
e6cb81e5-61a4-4b67-a668-d8a7d46b2cea
< 1.6.11
CRITICAL 9.8 The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo… — wordfence
e6977a58-cce0-4ae8-abe6-1870bbb2bf06
< 1.2.0
CRITICAL 9.8 The Youzify Plugin for WordPress is vulnerable to SQL injection via the 'youzify_media_pagination' AJAX action in versio… — wordfence
e675d64c-cbb8-4f24-9b6f-2597a97b49af
< 2.8.8
CRITICAL 9.8 The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress… — wordfence
e6553417-cb3d-40f4-b2ac-acd2d8d04f14 CRITICAL 9.8 The Login with QR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.… — wordfence
e5af0317-ef46-4744-9752-74ce228b5f37
< 0.9.124
CRITICAL 9.8 The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbi… — wordfence
e5a26786-2b15-43ce-a992-fd8cc9cf5600
< 1.3.8
CRITICAL 9.8 SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers … — wordfence
e582fa40-b03e-4194-b612-d139e981cce2
< 2.7
CRITICAL 9.8 The Display Widgets plugin for WordPress is vulnerable to a developer-created backdoor that injected SEOspam into sites … — wordfence
e57f7912-4af3-4dcb-b267-afec1c373b00
< 1.1.0
CRITICAL 9.8 The Wp-ImageZoom plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in the 'zoom.php' fi… — wordfence
e5539ad8-4203-4d22-9a40-0ed6e0471e19
< 2.2.2
CRITICAL 9.8 WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externa… — wordfence
e54abb3d-329b-4f9c-b562-db8a40cc7c97
< 7.8.5
CRITICAL 9.8 The Alone theme for WordPress is vulnerable to Remote Code Execution in versions up to 7.8.5. This is due to insufficien… — wordfence
e5441e7e-9be1-434e-9413-31920f565184
< 1.5.0
CRITICAL 9.8 The Krowd theme for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 1.5.0. This makes … — wordfence
e52b34fe-2414-4d6f-bf43-9c5b65ebf769
< 5.9.0
CRITICAL 9.8 The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all ve… — wordfence
e4fdc902-4cfe-4116-a294-9a0fcb2de346
< 4.14.4
CRITICAL 9.8 The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on t… — wordfence
← Prev 14 15 16 17 18 19 20 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top