🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 21 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
da807a8d-56de-494d-9f8a-9f749ab6c90e
< 1.8
CRITICAL 9.8 The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload via qquploader ajax file uploader. wordfence
da760bcf-b252-4b88-9f54-af0a097e3295
< 0.71
CRITICAL 9.8 PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute a… wordfence
da6eb803-3e2a-4ff1-9b93-6f109e8d0714
< 7.8.2
CRITICAL 9.8 The RSVPMaker plugin for WordPress is vulnerable to SQL Injection via the 'event_count' parameter called via the 'signed… wordfence
da590a65-8728-4577-b6e4-ecebc2a2277d
< 2.8
CRITICAL 9.8 The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeo… wordfence
da525d8d-9a69-4bb3-821a-948646c4ee2b
< 1.7.1
CRITICAL 9.8 The CozyStay theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.7.1. This makes it possible f… wordfence
da51b3ef-b12f-4af0-90b7-1ea61595b661
< 1.5.4
CRITICAL 9.8 The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in… wordfence
da44b8d8-3f3f-4791-9f45-dee5e60f9bcc CRITICAL 9.8 The Ach Invoice App plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.1. … wordfence
da3e3d6c-7643-4f22-aa88-2c4ce80aed1f
< 3.1.9
CRITICAL 9.8 The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via t… wordfence
da36ba83-490e-4c9d-8a34-c5c79392a09a
< 3.9.8
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'product_id' parameter … wordfence
da1d37f5-45d5-4775-a217-24fdb3b53da7
< 2.0.14
CRITICAL 9.8 The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.p… wordfence
da0f0e1a-bbf8-42a5-b330-b53134488ebd
< 1.0.4
CRITICAL 9.8 The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … wordfence
d9f6ef14-dc04-46da-b2fc-e84b91153bfe CRITICAL 9.8 SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress al… wordfence
d98d1782-a6cc-403a-b0fa-43282daa1136
< 2.5.9.1
CRITICAL 9.8 The DukaPress plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter in the 'dukapress/dow… wordfence
d96877a4-c5c0-429e-a7b8-03935c4b36fa CRITICAL 9.8 The Opstore theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.5. This make… wordfence
d9450e6b-df5e-4265-a3df-08cb10eb8dc0 CRITICAL 9.8 The Kiddo Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload… wordfence
d91a7cd4-929d-4df1-9557-ebd47e93c6e3
< 5.1.8
CRITICAL 9.8 The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to privilege escalation via account … wordfence
d8e849fb-76e0-427a-8e05-d340add1c150
< 2.2.13.7
CRITICAL 9.8 Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.6 and earlier for WordPress… wordfence
d8da513f-19b1-4ec4-b3ad-dc3a7bb6ab49
< 2.6.6.0
CRITICAL 9.8 The SP Projects & Document Manager plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and in… wordfence
d893edd0-8a60-43fd-94bb-3b52cea1d00e
< 3.0
CRITICAL 9.8 importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete… wordfence
d84b94b3-b4ef-400c-8d4c-6b52d839c239 CRITICAL 9.8 The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to… wordfence
d84ad258-8a0c-44b2-9897-03ad214e8493 CRITICAL 9.8 The Barclaycart plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … wordfence
d818b467-a893-4f4f-b623-abff99ef37b4 CRITICAL 9.8 The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via th… wordfence
d80ab1a4-19f9-4fea-87b4-1d2ba465e860
< 1.7.3
CRITICAL 9.8 The Web Directory Free plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, … wordfence
d7f024c5-80d8-490f-b448-9bccb877024b
< 1.1
CRITICAL 9.8 The Premium Courses & eLearning plugin for WordPress is vulnerable to SQL Injection via the ‘level_ids’ parameter in… wordfence
d7eb5fad-bb62-4f0b-ad52-b16c3e442b62
< 6.44
CRITICAL 9.8 The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi… wordfence
← Prev 18 19 20 21 22 23 24 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top