🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 26 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cd3a7af1-0cae-4872-9e61-58e9a9e3eda5
< 4.1.7
CRITICAL 9.8 The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious ac… wordfence
cd328738-7467-4f30-83bb-9e1c836fa940
< 6.00.03
CRITICAL 9.8 SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to e… wordfence
cd28ac3c-aaef-49e3-843d-8532404703c9
< 5.0.0
CRITICAL 9.8 The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… wordfence
cd00d716-535c-41eb-a766-82079e0060e6
< 3.4
CRITICAL 9.8 The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and in… wordfence
cccbdb49-d423-4955-a078-ae0acdb79804 CRITICAL 9.8 SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress … wordfence
cc748d31-b8e6-44b6-af30-944c0b0f1f0c
< 0.1.14
CRITICAL 9.8 The Omni Secure Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation v… wordfence
cc742fa0-7d10-4fe4-b95c-7d4ca563d402
< 6.7.2
CRITICAL 9.8 The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel. wordfence
cc550fd9-c332-4a40-b4a9-166d5ffebc76 CRITICAL 9.8 The My Geo Posts Free plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2 v… wordfence
cc2f8da1-7503-45e3-8a7d-0031ce264edf CRITICAL 9.8 The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the… wordfence
cc26d20e-3ecd-438e-a123-5015ecc17290
< 4.6.1
CRITICAL 9.8 The videowhisper-video-presentation plugin 4.1.4 and below for WordPress allows remote attackers to execute arbitrary co… wordfence
cc1cf03f-265c-4cb5-b32b-8039b9e5da2a
< 6.9.0
CRITICAL 9.8 The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX a… wordfence
cc0fbe84-e455-4e62-9c48-49340d08f81d CRITICAL 9.8 The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, a… wordfence
cc01bb79-67cd-40d8-b0e0-1853df1aa3c4 CRITICAL 9.8 The Product Catalog 8 plugin for WordPress is vulnerable to SQL Injection via the ‘selectedCategory’ parameter in ve… wordfence
cbbaa4bd-6460-4f2b-afb5-6bb973443902 CRITICAL 9.8 The Fitrush theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.4. This make… wordfence
cb866476-14c0-4ade-90b0-670418b397fb CRITICAL 9.8 The Webapp builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t… wordfence
cb7ee61d-2f2c-4e5e-891e-e8b7a5cd29fa CRITICAL 9.8 The Grip theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.9. This makes i… wordfence
cb603be6-4a12-49e1-b8cc-b2062eb97f16
< 6.72
CRITICAL 9.8 The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi… wordfence
cb5d3d64-a465-4c26-9cf7-7acc7dab862a CRITICAL 9.8 The Spicy Blogroll plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.0 vi… wordfence
cb55be41-c3aa-4f1e-9330-a31181a3a264
< 2.5.4
CRITICAL 9.8 The Shibboleth plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
cb334b74-5561-4ac7-b321-397600e26d06
< 1.4.4
CRITICAL 9.8 The Motors – Car Dealer, Classifieds & Listin plugin for WordPress is vulnerable to arbitrary file uploads due to miss… wordfence
cb2e9370-f50e-4792-99f6-4678e0256a56
< 3.0.61
CRITICAL 9.8 The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing… wordfence
cb1626ae-cf58-4377-ab4f-58e4536825fe CRITICAL 9.8 The Foodbakery Sticky Cart plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … wordfence
cb102a58-2fc0-4441-8f51-a6109e323878
< 1.1
CRITICAL 9.8 Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow re… wordfence
cae6e8b9-a8a9-41d3-83e8-d833515a0244
< 3.2
CRITICAL 9.8 The Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics plugin for WordPress is vulnerable to PHP O… wordfence
cadd47e9-1d5b-4f04-8421-7707dad53ea6
< 0.91
CRITICAL 9.8 The Google Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.90 via d… wordfence
← Prev 23 24 25 26 27 28 29 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top