πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 29 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c814924a-bdcd-4b73-905b-a469f4d37ddf
< 2.731
CRITICAL 9.8 The Post Pay Counter plugin before 2.731 for WordPress has PHP Object Injection via deserialization of untrusted input v… — wordfence
c7e3a8ee-9950-4da4-8450-8b5902b3b876
< 1.0.94
CRITICAL 9.8 The User Verification plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when gen… — wordfence
c7a97aeb-f34c-4997-864b-132bb5ed28e7
< 2.3.9
CRITICAL 9.8 The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL stateme… — wordfence
c7a6eff3-a592-4476-aff4-c133bb4e5870
< 1.1.23
CRITICAL 9.8 WordPress WP GPX Maps Plugin before 1.1.23 allows remote attackers to execute arbitrary PHP code via improper file uploa… — wordfence
c77619cd-8d14-42b9-a536-cf39c50e714a
< 0.5.4
CRITICAL 9.8 The Front End Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… — wordfence
c764e742-1135-43aa-a190-3b7ec6767f1c CRITICAL 9.8 The LogisticsHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … — wordfence
c764811f-e9dc-4c3d-b696-5792e70ff0b6 CRITICAL 9.8 The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stockt… — wordfence
c754d957-26a8-4fef-a487-96d566c2dc36
< 6.6.8
CRITICAL 9.8 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary … — wordfence
c74ce3e8-cab9-4cc6-a1ad-1e51f7268474
< 2.17.1
CRITICAL 9.8 The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all ve… — wordfence
c7476f2c-c32f-4ff7-ad32-70cf68387342
< 2.76
CRITICAL 9.8 The Disqus Comment System plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, … — wordfence
c741350a-e083-499c-992d-727f46ca57f9
< 1.1.2
CRITICAL 9.8 The simple-login-log plugin before 1.1.2 for WordPress has SQL injection via the 'order' parameter in the get_results fu… — wordfence
c726d8f0-7f2a-414b-9d73-a053921074d9
< 3.9.1
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This… — wordfence
c7214f90-a205-4d7e-94c8-ee07515ebbf1
< 1.4.7
CRITICAL 9.8 The Material Dashboard plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, … — wordfence
c714e2b3-8a96-4078-99a4-4ce620939828
< 1.4.12
CRITICAL 9.8 The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici… — wordfence
c6f68bfd-36c3-45f5-a50b-6803b5967e52 CRITICAL 9.8 The Download from files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… — wordfence
c6ef0c41-e498-4de6-a86a-d23f65a7a824
< 1.0.9
CRITICAL 9.8 controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users… — wordfence
c6ee9437-a12a-476b-9a4b-8da8d9fbfeb3
< 5.2.13
CRITICAL 9.8 The Fluent Forms Pro in version 6.2.7 and the Ninja Tables Pro in version 5.2.13 plugins for WordPress are vulnerable to… — wordfence
c6a0811e-f02b-49d1-915e-cf7ac4b5e1f5 CRITICAL 9.8 The Power Zoomer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via th… — wordfence
c6a02da1-b005-4fa9-9657-1c5f019f3858
< 2.0.8
CRITICAL 9.8 The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the '*_ordering' parameter in all versions … — wordfence
c6998185-0f9b-48ab-9dca-05adf5ae603a CRITICAL 9.8 The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerabl… — wordfence
c691d129-35db-4de8-a28e-5e77347e2280
< 1.15.20
CRITICAL 9.8 The Form Maker by 10Web plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid… — wordfence
c66d88a1-0936-40c4-adcf-ad79b9c57a80
< 4.4.3
CRITICAL 9.8 Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to exec… — wordfence
c63048ad-3d37-402e-8e61-415d2d6caa69 CRITICAL 9.8 The Form Lightbox plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check in th… — wordfence
c62d8146-e4b1-4c86-9d8a-c3a9bbfb0763
< 1.1.60
CRITICAL 9.8 The Profile Builder – User Profile & User Registration Forms Plugin for WordPress is vulnerable to authentication bypa… — wordfence
c5fee6e4-b985-4190-953b-133bc90e47da
< 1.6
CRITICAL 9.8 The Freshmail plugin for WordPress is vulnerable to Multiple SQL Injections via the 'include/wp_ajax_fm_form.php' and 'i… — wordfence
← Prev 26 27 28 29 30 31 32 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top