πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 18 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e24a3d15-da9a-4b47-949d-f95201760087
< 1.0.20
CRITICAL 9.8 The Morkva UA Shipping plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.… wordfence
e2427678-30cb-42fe-b6a2-f8b74db0bacf
< 6.0.0
CRITICAL 9.8 The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Privilege Escalation in a… wordfence
e2407d25-75da-4a04-8a39-04cb1711ae33 CRITICAL 9.8 The Easy Team Manager for WordPress is vulnerable to blind SQL Injection via the β€˜$_GET['id']’ parameter in versions… wordfence
e21bd924-1d96-4371-972a-5c99d67261cc
< 2.19
CRITICAL 9.8 The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is d… wordfence
e206ad70-c50d-46c3-b3d8-ad7305bfaa32
< 2.3.11
CRITICAL 9.8 The Premmerce Permalink Manager for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versio… wordfence
e1f9e09f-b69b-46e8-9793-8406956f54b3 CRITICAL 9.8 The Code Generator Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 due to … wordfence
e19f4cb9-09ec-4711-a799-1ba809f2eda8
< 4.02.01
CRITICAL 9.8 The formidable plugin before 4.02.01 for WordPress has unsafe deserialization. wordfence
e188b3a4-ddb2-405b-840f-4f13db5dbf3a
< 19.6.2
CRITICAL 9.8 The Rehub theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 19.6.1. This m… wordfence
e186123e-313f-4b0e-9579-135cfdfa4bc0
< 1.8.1
CRITICAL 9.8 The YITH Easy Login & Register Popup for WooCommerce plugin for WordPress is vulnerable to authorization bypass via pass… wordfence
e1634f86-21c0-4b9a-b521-c6b9986f91fc
< 6.67
CRITICAL 9.8 The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before … wordfence
e11e4bab-f8a9-4ecb-b36e-09a55e47f1ae CRITICAL 9.8 The Phlox Shop plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.0. T… wordfence
e110ea99-e2fa-4558-bcf3-942a35af0b91
< 2.8.3
CRITICAL 9.8 The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin f… wordfence
e0de1962-13bd-4710-ae1f-ab5ced7cc59d
< 1.8
CRITICAL 9.8 PHP remote file inclusion vulnerability in includes/generate-pdf.php in the WP ecommerce Shop Styling plugin for WordPre… wordfence
e0cb38a9-1084-47c9-9d62-9eff013fc341 CRITICAL 9.8 The Au Pair Agency - Babysitting & Nanny Theme theme for WordPress is vulnerable to PHP Object Injection in all versions… wordfence
e0ca6ac4-0d89-4601-94fc-cce5a0af9c56
< 5.7.15
CRITICAL 9.8 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… wordfence
e0906a45-6d9b-48a0-98ae-df7b591a8848 CRITICAL 9.8 The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and w… wordfence
e08d455e-925d-4a94-8d57-484aedc25411
< 1.5.0.5
CRITICAL 9.8 The Tipsacarrier plugin for WordPress is vulnerable to SQL Injection via the 'sidx' parameter in versions up to, but not… wordfence
e087d9ea-6d60-41db-a0b1-e14df2234c34
< 1.1.5
CRITICAL 9.8 The MemberGlut – Role & User Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up … wordfence
e068573d-bc3e-48de-b4e7-6a0666086ac3
< 7.1.9.8
CRITICAL 9.8 The Checkout Mestres WP plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up … wordfence
e062c794-1ab7-4d44-95da-40cd401f3a37 CRITICAL 9.8 TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote a… wordfence
e02683dc-0771-4bd5-bba3-2b5423da1c80 CRITICAL 9.8 The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and … wordfence
e001c522-0cfd-4698-b1f6-e6404bdd2f1b CRITICAL 9.8 The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f… wordfence
dffaf909-72f5-466f-8dd0-d46a81402caf
< 1.5.4
CRITICAL 9.8 The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. pl… wordfence
dfe41d6f-5026-4fcb-9ba0-a5180a03222c
< 1.2.3
CRITICAL 9.8 Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote a… wordfence
df946b56-f3a5-4b0e-b281-1632abf93b34
< 2.2.9
CRITICAL 9.8 Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated att… wordfence
← Prev 15 16 17 18 19 20 21 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top