πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 19 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
df8326b6-a443-4f76-a755-49f89af74d7e
< 4.0.12
CRITICAL 9.8 The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Admin… wordfence
df46b3d5-a433-47b5-99b8-117591f7dd16
< 3.0.34.2
CRITICAL 9.8 The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to code… wordfence
df086b87-b025-417f-adc0-5f2829024a0b
< 3.0.7
CRITICAL 9.8 SQL injection vulnerability in question.php in the mTouch Quiz before 3.0.7 for WordPress allows remote attackers to exe… wordfence
dee00cec-782a-406f-a918-c65cd80c56b0
< 2.3.13
CRITICAL 9.8 The stm-megamenu plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.3.12… wordfence
ded1b46e-b4b0-4f0d-929e-e1caf93576a7
< 1.0.68
CRITICAL 9.8 The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query para… wordfence
debed89a-dcae-41e3-945e-1cd592fdd1c9 CRITICAL 9.8 The robotcpa plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5 via the … wordfence
dea166d9-9f1b-42ad-a339-63c111679f85
< 1.4
CRITICAL 9.8 The NewsCard theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3. This makes… wordfence
de9f28b9-121d-42d5-9a7c-9caa52eb2e32
< 1.0.18
CRITICAL 9.8 The CoinPayments.net Payment Gateway for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versi… wordfence
de9c9e1e-3c3c-463a-a78c-d8bc7228da93
< 3.3.6
CRITICAL 9.8 The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied inp… wordfence
de9be7bc-4f8a-4393-8ebb-1b1f141b7585
< 5.1.2
CRITICAL 9.8 The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. T… wordfence
de8e7adc-3777-4fb1-a708-68da950e3d4f
< 1.1.0
CRITICAL 9.8 The MultiManager WP – Manage All Your WordPress Sites Easily plugin for WordPress is vulnerable to Authentication Bypa… wordfence
de4f8d45-9522-4a32-bc98-be8dbf3a5cf1
< 1.0.5.2
CRITICAL 9.8 The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, a… wordfence
de394637-7215-4fe7-8529-2d785deef0c8 CRITICAL 9.8 The Vmax Project Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including… wordfence
de33c461-a463-4ac1-91a2-3b168fb08b0b CRITICAL 9.8 The Nitan theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.9. This makes it… wordfence
de302cfb-5eea-4571-9bb3-44ad00262e14
< 7.3.12
CRITICAL 9.8 The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Authentication Bypass i… wordfence
de255530-6b2d-426b-9f80-dbfebd2e3307
< 3.3.1
CRITICAL 9.8 The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.… wordfence
ddf1cecd-c630-498d-9aa0-3d0adeb73033
< 17.8
CRITICAL 9.8 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient … wordfence
ddd25026-f507-47f0-bf4e-5b58c37f398c
< 1.2.5
CRITICAL 9.8 Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow … wordfence
ddc91762-b1b0-4d88-bf2d-04a35aab62b1
< 5.2.0
CRITICAL 9.8 The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before usi… wordfence
ddbbcd8a-d2ea-4c0c-98f0-a40080ac4a72 CRITICAL 9.8 The FW Gallery – Photo, video, audio media presentation and management system with players and slideshow plugin for Wo… wordfence
ddaed8e7-4a5e-440e-9a5f-4a92b3f63783
< 1.5.0
CRITICAL 9.8 The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up … wordfence
ddad1317-8152-4532-b0e8-b31d77021916
< 1.6.1
CRITICAL 9.8 The Grill and Chow theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. This… wordfence
dd977321-f901-4854-bba1-fc729dda688c
< 6.4.4
CRITICAL 9.8 The Fancy Product Designer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
dd8e9153-d84d-4510-9cc7-d24e56fd01db
< 2.0.8
CRITICAL 9.8 The Miraculous Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0… wordfence
dd7f3a48-d851-4533-967c-f0aa98bb85d1
< 3.7.0
CRITICAL 9.8 The SSL Wireless SMS Notification plugin for WordPress is vulnerable to privilege escalation in all versions up to, and … wordfence
← Prev 16 17 18 19 20 21 22 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top