πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 22 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d7d6d15c-067f-44cb-bd61-ff39bed7e356
< 4.9.28
CRITICAL 9.8 The UserPro plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 4.9.27. This ma… wordfence
d7c94c68-bf3c-49b0-b7eb-39374c6002aa CRITICAL 9.8 The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter… wordfence
d792be47-bbca-4d94-95b3-194acf3f57b3 CRITICAL 9.8 The Background animation blocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… wordfence
d748e0f8-fe00-4751-9c24-561fd27e62c3
< 1.8.4
CRITICAL 9.8 The WooCommerce – Store Exporter plugin for WordPress is vulnerable to authorization bypass due to a missing capabilit… wordfence
d73ca391-97a3-4701-8429-e73f5914e65e
< 1.26
CRITICAL 9.8 The RokStories plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '… wordfence
d7261e93-2341-4e14-a9b3-8fec295f6cde
< 3.5.1.36
CRITICAL 9.8 The Smart Slider 3 Pro plugin for WordPress contains a malicious backdoor in version 3.5.1.35. This is due to a supply c… wordfence
d722ec8d-bfca-4da1-8eb0-8d33735c5e44 CRITICAL 9.8 The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,… wordfence
d7140a6e-a528-428e-850e-5e4a481c5d7d
< 4.8
CRITICAL 9.8 The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. … wordfence
d6f68904-e575-457d-9040-c791b645e6c8
< 1.35.1
CRITICAL 9.8 The WP Property plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … wordfence
d6d6391a-542a-41c1-8eec-07ad5e77abdd
< 0.7.9
CRITICAL 9.8 The Restaurant Zone theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… wordfence
d6b6d824-51d3-4da9-a39a-b957368df4dc
< 3.2.6
CRITICAL 9.8 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union ba… wordfence
d6ac2996-098f-474c-b44e-78d5af7b503a
< 3.5.4
CRITICAL 9.8 The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 … wordfence
d6a4872e-0f62-44b1-b77e-0817b065980f
< 2.98
CRITICAL 9.8 The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay… wordfence
d68d2144-96b9-482e-9791-c3506661596e
< 2.0.6
CRITICAL 9.8 The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter when conducting job searc… wordfence
d68a2b60-ee89-4231-b256-214eba418244
< 3.3.1
CRITICAL 9.8 The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3… wordfence
d6686b67-8648-4f1b-8e05-fa67db60c8aa
< 12.5
CRITICAL 9.8 The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to arbitrary … wordfence
d6226ae5-3b75-4521-b060-004f291203c7
< 5.5.3.7
CRITICAL 9.8 SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitr… wordfence
d5c0c64c-7105-4bc3-b42d-89cfa44d02b9
< 2.2
CRITICAL 9.8 The ChurcHope theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1 via the 'f… wordfence
d5bf199d-5607-48d5-adcd-211ded2087d4 CRITICAL 9.8 The JP Students Result Management System Premium plugin for WordPress is vulnerable to arbitrary file uploads due to mis… wordfence
d5b695d7-c690-4748-b218-5699d1aa63bf
< 2.0.0
CRITICAL 9.8 The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension … wordfence
d5ab090c-14fd-4d58-a915-fd68e5eaefe1
< 1.1.9
CRITICAL 9.8 Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.9 for WordPress allows remote… wordfence
d590e730-ad5f-4046-b897-c3b8aed250b3
< 6.0.7.2
CRITICAL 9.8 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
d571e741-6d72-47fe-8eb0-8a75c173f626 CRITICAL 9.8 The Simple Dashboard plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.… wordfence
d56cfeb1-1257-4f6b-b889-d9f5839ce60d
< 1.1.15
CRITICAL 9.8 The Sapa theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.14. This makes … wordfence
d5400ec0-383b-4ac5-9b38-44533519e44d
< 5.1.8
CRITICAL 9.8 The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated an… wordfence
← Prev 19 20 21 22 23 24 25 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top