πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 23 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d534feae-d1b7-4544-b1c5-c23f37dd5bab
< 1.1.7
CRITICAL 9.8 The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This i… wordfence
d52f601b-6a80-4b6f-895b-fcbbdf73103a
< 1.9.1.5
CRITICAL 9.8 The 3DPrint Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… wordfence
d52983d1-7da4-44e6-bfed-75107b923267 CRITICAL 9.8 The Kish Guest Posting plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
d5209e18-894e-46fa-9eb1-11016ef41104
< 2.5.4
CRITICAL 9.8 The Custom Login Page Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all … wordfence
d51d8b79-04ff-470f-92da-12eb72ac023a CRITICAL 9.8 The WP Ticket Ultra Help Desk & Support Plugin plugin for WordPress is vulnerable to Local File Inclusion in all version… wordfence
d4f3d386-98cc-4b5a-b13f-841e812bb37f
< 3.0.1
CRITICAL 9.8 Unspecified vulnerability in the folder framework in the Enfold theme before 3.0.1 for WordPress has unknown impact and … wordfence
d4e1ca02-4eb5-4a46-99d5-89630f37d9ed CRITICAL 9.8 The Steveas WP Live Chat Shoutbox plugin for WordPress is vulnerable to SQL Injection via several parameters in versions… wordfence
d4bce9d1-38b9-4c25-b5dc-fd9dedfc3ede
< 1.3.3
CRITICAL 9.8 The WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) plugin for WordPress… wordfence
d4ae4e05-cdbf-481f-abcc-9704e75ec8ad
< 1.6.0
CRITICAL 9.8 The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 pa… wordfence
d4994d7d-82f7-4cb0-869f-e27abe04b621
< 1.7.1
CRITICAL 9.8 The Knews Multilingual Newsletters plugin for WordPress is vulnerable to generic SQL Injection via an unknown parameter … wordfence
d4837258-c749-4194-926c-22b67e20c1fc
< 2.9.6
CRITICAL 9.8 The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to… wordfence
d4804081-67b1-4c62-af8e-bdbcea2ba6e7
< 8.0.0
CRITICAL 9.8 The WP Support Plus Responsive Ticket System plugin for WordPress is vulnerable to Authentication Bypass in versions up … wordfence
d44f8af2-3525-4b00-afa8-a908250cc838
< 0.9.2.2
CRITICAL 9.8 The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a… wordfence
d42eeda5-7034-4544-be97-8064ff6d3185 CRITICAL 9.8 Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attacker… wordfence
d4095518-0daf-4cfe-a521-86fb1c927f51
< 4.00
CRITICAL 9.8 A SQL injection issue was discovered in the Quick Chat plugin before 4.00 for WordPress. wordfence
d3af64a2-3bd6-47af-919e-00c5249dcc74
< 1.2.1
CRITICAL 9.8 The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the W… wordfence
d3a5be68-8073-48b0-a536-bb3a05e83dda CRITICAL 9.8 The EduKart Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. … wordfence
d3a4fa4d-a7d2-4890-b0f5-5fe69bc5e7ac
< 2.13.8
CRITICAL 9.8 The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPr… wordfence
d34f4e77-f384-4d84-be32-0d349962b614
< 5.5.2
CRITICAL 9.8 The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass… wordfence
d323d28f-280c-49cd-b7f7-3e272ea62549 CRITICAL 9.8 A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/list… wordfence
d257d0e0-7e42-49d5-83c6-f5c44f2e15fc
< 1.2.2
CRITICAL 9.8 The WP Marketplace – Complete Shopping Cart / eCommerce Solution plugin for WordPress is vulnerable to arbitrary file … wordfence
d2448afc-70d1-4dd5-b73b-62d182ee9a8a
< 6.26.13
CRITICAL 9.8 The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptogra… wordfence
d22fb2e8-bb61-49bc-9fab-8f7c58339a69
< 3.7.3
CRITICAL 9.8 The Custom 404 Pro plugin for WordPress is vulnerable to blind SQL Injection via multiple parameters including the 'User… wordfence
d21cf285-9d75-43a2-9e81-67116f0bf896
< 5.2
CRITICAL 9.8 The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldu… wordfence
d1e8412a-f2fb-4f90-9847-1e4043dda480
< 1.0.7
CRITICAL 9.8 The Simplified Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
← Prev 20 21 22 23 24 25 26 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top