🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 18 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e4d51a0c-c625-4732-b345-df02971fbffa
< 2.4.8
CRITICAL 9.8 The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. Th… — wordfence
e4bede17-d174-42d0-a25e-bf7fe10e4206
< 1.2.9
CRITICAL 9.8 The Quentn WP plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.8. Th… — wordfence
e49c7b2a-5241-4762-b7c9-c33b1ac4a668 CRITICAL 9.8 The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and… — wordfence
e4941cce-c6c0-4e8a-859e-cf0f50f92ce6
< 2.4.15
CRITICAL 9.8 The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it i… — wordfence
e47f6c33-1a4b-4c4c-8323-99d06ce0731a CRITICAL 9.8 The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Cont… — wordfence
e44c5dc0-6bf6-417a-9383-b345ff57ac32
< 2.1.1
CRITICAL 9.8 The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnera… — wordfence
e391f560-2037-4180-a77e-1731524a318c
< 2.0.4
CRITICAL 9.8 The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deseria… — wordfence
e353a269-c7f5-4b6a-9f9e-be459ead0335
< 59.4
CRITICAL 9.8 The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions su… — wordfence
e34eed57-ffcb-43ae-98e4-fd0e16be3310 CRITICAL 9.8 The MagicForm plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 0.1.3. This … — wordfence
e342b1c0-6e7f-4e2c-8a52-018df12c12a0
< 2.4.5
CRITICAL 9.8 The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… — wordfence
e30b62de-7280-4c29-b882-dfa83e65966b
< 2.7.0
CRITICAL 9.8 The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versi… — wordfence
e2b24858-dfcd-46f3-9552-c7acc63a1ee7
< 3.6.1
CRITICAL 9.8 The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the… — wordfence
e28ae1a3-abc6-484c-abc7-1e0b958fa30b
< 1.5.8
CRITICAL 9.8 The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, a… — wordfence
e2837399-c44f-494e-bdc6-f9c6e4e2dc11
< 2.7
CRITICAL 9.8 The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to,… — wordfence
e27c1d20-cef7-4801-beb9-adaeb1b95145 CRITICAL 9.8 Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membe… — wordfence
e27971a3-f84c-4f13-81af-127e7560566a
< 5.2.5
CRITICAL 9.8 The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation … — wordfence
e26a1c7c-8c4d-450d-bbfa-6ab1af4bceba
< 2.3.0
CRITICAL 9.8 The Tevolution Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … — wordfence
e24c9e9a-4f18-41b6-a0b7-700fecb5d3e6 CRITICAL 9.8 The Sayfa Sayaç plugin for WordPress is vulnerable to SQL Injection via the in versions up to, and including, 2.6 due t… — wordfence
e24a3d15-da9a-4b47-949d-f95201760087
< 1.0.20
CRITICAL 9.8 The Morkva UA Shipping plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.… — wordfence
e2427678-30cb-42fe-b6a2-f8b74db0bacf
< 6.0.0
CRITICAL 9.8 The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Privilege Escalation in a… — wordfence
e2407d25-75da-4a04-8a39-04cb1711ae33 CRITICAL 9.8 The Easy Team Manager for WordPress is vulnerable to blind SQL Injection via the ‘$_GET['id']’ parameter in versions… — wordfence
e21bd924-1d96-4371-972a-5c99d67261cc
< 2.19
CRITICAL 9.8 The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is d… — wordfence
e206ad70-c50d-46c3-b3d8-ad7305bfaa32
< 2.3.11
CRITICAL 9.8 The Premmerce Permalink Manager for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versio… — wordfence
e1f9e09f-b69b-46e8-9793-8406956f54b3 CRITICAL 9.8 The Code Generator Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 due to … — wordfence
e19f4cb9-09ec-4711-a799-1ba809f2eda8
< 4.02.01
CRITICAL 9.8 The formidable plugin before 4.02.01 for WordPress has unsafe deserialization. — wordfence
← Prev 15 16 17 18 19 20 21 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top