πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 2 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9b41efbd-bd47-415f-8de7-f30b3a7cf326 CRITICAL 10.0 The Imperial Fairytale Theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal i… wordfence
99746867-597b-49df-aa9e-548456a58542 CRITICAL 10.0 The Photocrati Theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all ve… wordfence
98cf2a10-cc53-4479-87d1-71489f6a8c51
< 3.5.3
CRITICAL 10.0 The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 v… wordfence
971d40d2-428f-49d9-8918-89843980f177
< 1.0.4
CRITICAL 10.0 The TrueBooker – Appointment Booking and Scheduler Plugin. plugin for WordPress is vulnerable to SQL Injection in all … wordfence
93e2d007-8157-42c5-92ad-704dc80749a3
< 3.14.2
CRITICAL 10.0 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… wordfence
929fd4e6-9040-41cb-98f0-0cfdd80caf42
< 9.5.1
CRITICAL 10.0 The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… wordfence
8df5c412-e995-411f-94a9-afd7f9941125
< 6.9.8
CRITICAL 10.0 The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.9.7 due t… wordfence
82802e80-efb5-4aa3-9fea-9c21bfb71efa
< 2.9
CRITICAL 10.0 The Real3D Flipbook plugin for WordPress is vulnerable to Unauthenticated File or Directory Delete in versions up to, an… wordfence
813821c8-a9f9-408e-b85e-1c24d90f5e4a
< 16.26.6
CRITICAL 10.0 The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection in all vers… wordfence
7dbf982f-c83f-4980-b758-9e241e0de67b CRITICAL 10.0 The Customify Site Library plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includ… wordfence
7b57e750-71ec-4c52-999b-6c14a78c3bff
< 1.4.5
CRITICAL 10.0 The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion … wordfence
7887e0a6-53bf-49c7-a7a6-7c65cec28cae CRITICAL 10.0 The RocketTheme's Refraction Theme is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in versio… wordfence
76dc5fc0-adb9-401c-ab50-e0cb23a88fa3
< 2.9.5
CRITICAL 10.0 The ListingPro theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.4 due to insuffi… wordfence
71782003-3fbf-44d3-a5fd-7370acff2eea
< 6.6.9
CRITICAL 10.0 The PayPlus Payment Gateway plugin for WordPress is vulnerable SQL Injection in all versions up to, and including, 6.6.8… wordfence
712887d9-25fd-4d8f-a2e6-e6f2855f5ddb CRITICAL 10.0 The Music theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all known v… wordfence
683cc327-e17e-49f6-a903-f8a40bb832d1
< 9.3.9
CRITICAL 10.0 The XStore theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.3.8 due to insufficien… wordfence
6827dc47-669c-41de-8716-7932ce8e5259 CRITICAL 10.0 The Revy plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all version… wordfence
659fcb95-9041-443e-9b75-0d2f8c6108aa
< 5.8.0
CRITICAL 10.0 The WP Travel Engine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.9 due to … wordfence
6598d171-e68c-4d2f-9cd1-f1574fa90433
< 1.4.5
CRITICAL 10.0 The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1… wordfence
5fc5fb44-8264-46b7-9486-f145d6cbfde2
< 3.2.16
CRITICAL 10.0 The Cost Calculator Builder plugin for WordPress is vulnerable to SQL Injection via discount codes in versions up to, an… wordfence
5f800156-1ccc-431f-9b2b-3b2ba3428bbc
< 4.14.8
CRITICAL 10.0 The Realtyna Organic IDX plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.… wordfence
5baec449-59f9-47f3-af80-eb31adeacb7a
< 0.2.42
CRITICAL 10.0 The ActiveDEMAND plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… wordfence
5a3e2d1c-8879-4def-8861-3d6d8b683b7e
< 2.7.4
CRITICAL 10.0 The BuddyPress plugin for WordPress is vulnerable to Arbitrary File Deletion in versions 2.0 - 2.7.3. This allows unauth… wordfence
5931ad4e-7de3-41ac-b783-f7e58aaef569
< 2.1.1
CRITICAL 10.0 The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/r… wordfence
56d24bc8-4a1a-4e60-aec5-960703a6058a
< 1.6.4
CRITICAL 10.0 Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A m… wordfence
← Prev 1 2 3 4 5 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top