🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 26 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2025-12981 CRITICAL 9.8 The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This i… — nvd
CVE-2025-12882 CRITICAL 9.8 The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. … — nvd
cfffe880-e3f9-4163-a726-e248433e1034
< 2.3.30
CRITICAL 9.8 The My Calendar plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.3.29 via the '… — wordfence
cff74b3d-f056-4e9f-a62d-a3d79b4f4d56
< 3.1
CRITICAL 9.8 The Car Rental System plugin for WordPress is vulnerable to blind SQL Injection via the ‘pickuploc’ and 'dropoff' pa… — wordfence
cfe5d24a-a2ed-46c1-8d9b-9bd2c63cb8b3 CRITICAL 9.8 The MoveTo plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including… — wordfence
cfd32e46-a4fc-4c10-b546-9f9da75db791
< 2.3.8
CRITICAL 9.8 The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is … — wordfence
cf85ddc7-cb90-4502-9936-f2c51030b4a6 CRITICAL 9.8 The Disc Golf Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.0… — wordfence
cf851bed-f5d8-44e2-810d-906ba3d3c1c5
< 33.0.16
CRITICAL 9.8 The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads… — wordfence
cf3df923-9426-4e5b-ba59-eda0b5c18d40
< 2.3.1
CRITICAL 9.8 The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1… — wordfence
cf34eb9f-f6e9-4a7a-8459-c86f9fa3dad8
< 1.7.27
CRITICAL 9.8 The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including… — wordfence
cf24216c-7882-4359-b526-44d845de0249 CRITICAL 9.8 The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to e… — wordfence
cf159a11-9490-4f79-a62d-c279cfe26108 CRITICAL 9.8 The Ripe HD FLV plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in the 'config.php' f… — wordfence
cef83a3e-9e8b-4c4c-9adc-cdcebefadd39 CRITICAL 9.8 The Image Gallery with Slideshow plugin for WordPress is vulnerable to generic SQL Injection via the ‘gid’ parameter… — wordfence
cecffd72-4597-4308-9f21-4731269e8cf1
< 3.45
CRITICAL 9.8 A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitat… — wordfence
cece751c-400d-42b4-9438-950d5aca51fc
< 3.0.4
CRITICAL 9.8 The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… — wordfence
ce8ec66f-5efc-4354-8871-8e35ab4e51fc
< 1.6.2
CRITICAL 9.8 The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions u… — wordfence
ce834ae1-e05a-4b0e-9d7f-144669437d70
< 1.7.7
CRITICAL 9.8 The Caldera Forms Pro plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on th… — wordfence
ce544dd0-6e4a-4a73-bba0-db2d667e378e
< 3.1.2
CRITICAL 9.8 The Pie Register plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions before 3.1.2 d… — wordfence
ce4c4395-6d1a-4d5f-885f-383e5c44c0f8
< 2.7.1
CRITICAL 9.8 The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due … — wordfence
ce3ae202-1227-4247-9133-5c7284392c9f
< 2.0.0
CRITICAL 9.8 The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin fo… — wordfence
ce38401f-443b-42b8-ae4e-53700f25bee7
< 1.6.11
CRITICAL 9.8 The Seofy Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.8. This … — wordfence
ce332037-bfa3-42a6-a352-ba13439db62f
< 1.0.53.1
CRITICAL 9.8 The Capie theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.40. This makes… — wordfence
ce119965-01a0-4cff-a0b2-e99bceb1406c
< 6.6.8
CRITICAL 9.8 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File… — wordfence
ce0dcbe6-9231-45d9-9658-5d775e02cfcb
< 4.1.1
CRITICAL 9.8 The Estatik Real Estate Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… — wordfence
cdbf2658-b819-4fd3-ac89-8b90a7e3a2cf
< 7.11
CRITICAL 9.8 The Social Share, Social Login and Social Comments plugin for WordPress is vulnerable to authorization bypass due to a m… — wordfence
← Prev 23 24 25 26 27 28 29 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top