🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 24 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d1cd5209-7959-49ae-a363-5fb4f06e2aec
< 2.4.11
CRITICAL 9.8 The Five Star Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to PHP Object Injection in all versio… wordfence
d1cc604a-b3dc-4dc1-b20b-4021b5b7d426
< 2.72
CRITICAL 9.8 The wp-polls plugin before 2.72 for WordPress has SQL injection. wordfence
d10672ba-ae98-43e8-9ad8-2b12e2b7bc49 CRITICAL 9.8 The Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin for WordPress is vulnerable to Remote Code Execut… wordfence
d1043dce-628f-485b-bc1c-b78938c2a6f5
< 2.4.4
CRITICAL 9.8 The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via acco… wordfence
d0fb6bf0-48b8-48cc-8080-8fe19c36ce7c
< 2.6.6
CRITICAL 9.8 The Dendelion theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the up… wordfence
d0fa6998-b85a-413e-be00-81926b4ea6ab CRITICAL 9.8 The Telecash Ricaricaweb plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.… wordfence
d0dd4fc0-1c6a-4556-b219-893563a27a69
< 3.0.2
CRITICAL 9.8 The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret managemen… wordfence
d0b27bc8-617a-4f98-954f-e49f87dca311
< 3.6.11
CRITICAL 9.8 The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via… wordfence
d0ad02d9-546f-4bcb-b567-785e3acfb489
< 1.1.0
CRITICAL 9.8 The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t… wordfence
d0ace3b6-7941-43c6-b636-8f7b9d51da3e
< 8.1.15
CRITICAL 9.8 The Level Four Store Front plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
d0966138-b28b-4c03-a2cf-b51c5f478276 CRITICAL 9.8 The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to,… wordfence
d07b5377-ce5f-4faa-ac72-78f5175913c3 CRITICAL 9.8 The Magazine Basic plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter due to insuffi… wordfence
d0538778-5ba4-4bec-a89d-ef90a9ba8375
< 3.1.8.7
CRITICAL 9.8 The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6… wordfence
d03b4dcd-297d-4361-9cc4-6ccf3d4f0e85 CRITICAL 9.8 The Pyrmont V2 theme for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and includin… wordfence
CVE-2026-7637 CRITICAL 9.8 The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deseria… nvd
CVE-2026-3535 CRITICAL 9.8 The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type val… nvd
CVE-2026-1994
< 260215
CRITICAL 9.8 The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and … nvd
CVE-2026-1555 CRITICAL 9.8 The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_i… nvd
CVE-2026-1405 CRITICAL 9.8 The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… nvd
CVE-2026-0926 CRITICAL 9.8 The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.… nvd
CVE-2025-13851 CRITICAL 9.8 The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user re… nvd
CVE-2025-13563 CRITICAL 9.8 The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3… nvd
CVE-2025-12981 CRITICAL 9.8 The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This i… nvd
CVE-2025-12882 CRITICAL 9.8 The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. … nvd
cfffe880-e3f9-4163-a726-e248433e1034
< 2.3.30
CRITICAL 9.8 The My Calendar plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.3.29 via the '… wordfence
← Prev 21 22 23 24 25 26 27 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top