πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 19 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e188b3a4-ddb2-405b-840f-4f13db5dbf3a
< 19.6.2
CRITICAL 9.8 The Rehub theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 19.6.1. This m… — wordfence
e186123e-313f-4b0e-9579-135cfdfa4bc0
< 1.8.1
CRITICAL 9.8 The YITH Easy Login & Register Popup for WooCommerce plugin for WordPress is vulnerable to authorization bypass via pass… — wordfence
e1634f86-21c0-4b9a-b521-c6b9986f91fc
< 6.67
CRITICAL 9.8 The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before … — wordfence
e11e4bab-f8a9-4ecb-b36e-09a55e47f1ae CRITICAL 9.8 The Phlox Shop plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.0. T… — wordfence
e110ea99-e2fa-4558-bcf3-942a35af0b91
< 2.8.3
CRITICAL 9.8 The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin f… — wordfence
e0de1962-13bd-4710-ae1f-ab5ced7cc59d
< 1.8
CRITICAL 9.8 PHP remote file inclusion vulnerability in includes/generate-pdf.php in the WP ecommerce Shop Styling plugin for WordPre… — wordfence
e0cb38a9-1084-47c9-9d62-9eff013fc341 CRITICAL 9.8 The Au Pair Agency - Babysitting & Nanny Theme theme for WordPress is vulnerable to PHP Object Injection in all versions… — wordfence
e0ca6ac4-0d89-4601-94fc-cce5a0af9c56
< 5.7.15
CRITICAL 9.8 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… — wordfence
e0906a45-6d9b-48a0-98ae-df7b591a8848 CRITICAL 9.8 The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and w… — wordfence
e08d455e-925d-4a94-8d57-484aedc25411
< 1.5.0.5
CRITICAL 9.8 The Tipsacarrier plugin for WordPress is vulnerable to SQL Injection via the 'sidx' parameter in versions up to, but not… — wordfence
e087d9ea-6d60-41db-a0b1-e14df2234c34
< 1.1.5
CRITICAL 9.8 The MemberGlut – Role & User Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up … — wordfence
e068573d-bc3e-48de-b4e7-6a0666086ac3
< 7.1.9.8
CRITICAL 9.8 The Checkout Mestres WP plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up … — wordfence
e0642c85-ee01-497c-8dc3-42e3ffc02995 CRITICAL 9.8 The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This mak… — wordfence
e062c794-1ab7-4d44-95da-40cd401f3a37 CRITICAL 9.8 TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote a… — wordfence
e02683dc-0771-4bd5-bba3-2b5423da1c80 CRITICAL 9.8 The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and … — wordfence
e001c522-0cfd-4698-b1f6-e6404bdd2f1b CRITICAL 9.8 The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f… — wordfence
dffaf909-72f5-466f-8dd0-d46a81402caf
< 1.5.4
CRITICAL 9.8 The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. pl… — wordfence
dfe41d6f-5026-4fcb-9ba0-a5180a03222c
< 1.2.3
CRITICAL 9.8 Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote a… — wordfence
df946b56-f3a5-4b0e-b281-1632abf93b34
< 2.2.9
CRITICAL 9.8 Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated att… — wordfence
df8326b6-a443-4f76-a755-49f89af74d7e
< 4.0.12
CRITICAL 9.8 The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Admin… — wordfence
df47132a-c4c2-457a-a82e-4df28e7d0c54
< 4.2.10
CRITICAL 9.8 The Gift Cards For WooCommerce Pro plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and in… — wordfence
df46b3d5-a433-47b5-99b8-117591f7dd16
< 3.0.34.2
CRITICAL 9.8 The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to code… — wordfence
df36eae9-6f2b-432c-a765-57450939b344
< 1.10.82
CRITICAL 9.8 The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all … — wordfence
df086b87-b025-417f-adc0-5f2829024a0b
< 3.0.7
CRITICAL 9.8 SQL injection vulnerability in question.php in the mTouch Quiz before 3.0.7 for WordPress allows remote attackers to exe… — wordfence
def1f99c-9d08-4971-82fe-bf74551542a8
< 3.1.8.8
CRITICAL 9.8 The Bricksforge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, a… — wordfence
← Prev 16 17 18 19 20 21 22 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top