🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 27 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cdb35927-b239-4243-a2d0-2e2c2cc61668
< 1.5.0
CRITICAL 9.8 The WP Fundraising Donation and Crowdfunding Platform WordPress plugin through 1.4.2 does not sanitise and escape a para… — wordfence
cd8a45c9-ca48-4ea6-b34e-f05206f16155
< 1.8.90
CRITICAL 9.8 The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… — wordfence
cd4f7b73-947b-4962-9880-5f279580f43c
< 3.20.0
CRITICAL 9.8 The Yith WooCommerce Gift Cards Premium plugin for WordPress is vulnerable to arbitrary file uploads due to missing file… — wordfence
cd3a7af1-0cae-4872-9e61-58e9a9e3eda5
< 4.1.7
CRITICAL 9.8 The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious ac… — wordfence
cd328738-7467-4f30-83bb-9e1c836fa940
< 6.00.03
CRITICAL 9.8 SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to e… — wordfence
cd28ac3c-aaef-49e3-843d-8532404703c9
< 5.0.0
CRITICAL 9.8 The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… — wordfence
cd00d716-535c-41eb-a766-82079e0060e6
< 3.4
CRITICAL 9.8 The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and in… — wordfence
cccbdb49-d423-4955-a078-ae0acdb79804 CRITICAL 9.8 SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress … — wordfence
cc748d31-b8e6-44b6-af30-944c0b0f1f0c
< 0.1.14
CRITICAL 9.8 The Omni Secure Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation v… — wordfence
cc742fa0-7d10-4fe4-b95c-7d4ca563d402
< 6.7.2
CRITICAL 9.8 The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel. — wordfence
cc550fd9-c332-4a40-b4a9-166d5ffebc76 CRITICAL 9.8 The My Geo Posts Free plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2 v… — wordfence
cc2f8da1-7503-45e3-8a7d-0031ce264edf CRITICAL 9.8 The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the… — wordfence
cc2ccfeb-6df6-4fee-96a5-94f8dd131f7c
< 6.17.3.1
CRITICAL 9.8 The "The Events Calendar" plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi… — wordfence
cc26d20e-3ecd-438e-a123-5015ecc17290
< 4.6.1
CRITICAL 9.8 The videowhisper-video-presentation plugin 4.1.4 and below for WordPress allows remote attackers to execute arbitrary co… — wordfence
cc1cf03f-265c-4cb5-b32b-8039b9e5da2a
< 6.9.0
CRITICAL 9.8 The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX a… — wordfence
cc0fbe84-e455-4e62-9c48-49340d08f81d CRITICAL 9.8 The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, a… — wordfence
cc01bb79-67cd-40d8-b0e0-1853df1aa3c4 CRITICAL 9.8 The Product Catalog 8 plugin for WordPress is vulnerable to SQL Injection via the ‘selectedCategory’ parameter in ve… — wordfence
cbc32e6d-47c5-4050-ba77-5a54203fe56a CRITICAL 9.8 The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in… — wordfence
cbbaa4bd-6460-4f2b-afb5-6bb973443902 CRITICAL 9.8 The Fitrush theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.4. This make… — wordfence
cb866476-14c0-4ade-90b0-670418b397fb CRITICAL 9.8 The Webapp builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t… — wordfence
cb7ee61d-2f2c-4e5e-891e-e8b7a5cd29fa CRITICAL 9.8 The Grip theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.9. This makes i… — wordfence
cb603be6-4a12-49e1-b8cc-b2062eb97f16
< 6.72
CRITICAL 9.8 The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi… — wordfence
cb5d3d64-a465-4c26-9cf7-7acc7dab862a CRITICAL 9.8 The Spicy Blogroll plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.0 vi… — wordfence
cb55be41-c3aa-4f1e-9330-a31181a3a264
< 2.5.4
CRITICAL 9.8 The Shibboleth plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… — wordfence
cb334b74-5561-4ac7-b321-397600e26d06
< 1.4.4
CRITICAL 9.8 The Motors – Car Dealer, Classifieds & Listin plugin for WordPress is vulnerable to arbitrary file uploads due to miss… — wordfence
← Prev 24 25 26 27 28 29 30 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top