πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 3 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
54a37c4a-44c7-47fd-8f2d-486372fb643c CRITICAL 10.0 The Viral Signup – limited opt-in with viral refferal sharing plugin for WordPress is vulnerable to SQL Injection in a… wordfence
5432bdd1-9b56-4f74-a468-011f942bdd89 CRITICAL 10.0 The Slash WP theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all vers… wordfence
51fd6124-4954-4827-a665-c2d94d74a512
< 1.4.1
CRITICAL 10.0 The VikRentCar plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.0 due to insuff… wordfence
43a7f1b0-c2c0-4832-9819-22625c8b727e
< 2.5.27
CRITICAL 10.0 The HTML5 Video Player – Best WordPress Video Player Plugin and Block plugin for WordPress is vulnerable to SQL Inject… wordfence
4143febf-92b3-42e7-9499-9ea83d7727d9
< 7.3
CRITICAL 10.0 The Chauffeur Taxi Booking System for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to miss… wordfence
3df23ba9-337f-49ac-9d1f-6b993430a1ce CRITICAL 10.0 The Propovoice Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.0.3 due to … wordfence
3aca0d51-6f70-4f35-873a-e23b4d7bae41 CRITICAL 10.0 The WpStickyBar – Sticky Bar, Sticky Header plugin for WordPress is vulnerable to SQL Injection via the 'banner_id' pa… wordfence
32df7bdb-d99d-4548-8960-3fefdf635753
< 1.94
CRITICAL 10.0 The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to SQL Injection via the 'onesignal_ext… wordfence
312a6601-c914-4661-82ff-6f8bac849442 CRITICAL 10.0 The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to ins… wordfence
2eaa5a5c-c11f-40d0-be69-c3ec8029a819
< 2.0.0
CRITICAL 10.0 The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
2c4c13c9-6f43-4a4d-b825-e246bf9a1e9c
< 5.7.9
CRITICAL 10.0 The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.8 due to insu… wordfence
25999d1f-9085-4410-b76a-3570f2517bdd
< 1.7.0
CRITICAL 10.0 The Docket (WooCommerce Collections / Wishlist / Watchlist) plugin for WordPress is vulnerable to SQL Injection in versi… wordfence
226e772e-6973-4ff0-9a02-5be503f292c8
< 2.0.1
CRITICAL 10.0 The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… wordfence
21da3c10-72b9-4c04-8586-dcf6dcf55852
< 7.0.1
CRITICAL 10.0 The Woocommerce OpenPos plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.4.4 due … wordfence
20fdbe6b-45a8-41f4-8dde-35a0f9ea04a1
< 3.3.1
CRITICAL 10.0 The Easy Digital Downloads plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.12 … wordfence
1feb3fa0-5fd9-443a-830c-cb1700ff30df
< 1.8
CRITICAL 10.0 The Layouts for Elementor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check… wordfence
191c3c86-0704-4d3c-b7ba-22cefbdc65f1
< 3.26.7
CRITICAL 10.0 The WishList Member X plugin for WordPress is vulnerable SQL Injection in versions up to, and including, 3.25.1 due to i… wordfence
1829b4b7-5042-4972-ad05-e9a7adbf3026
< 2.7.97
CRITICAL 10.0 Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attacke… wordfence
1261ad29-e4c1-4385-9f41-d3f3eecbb7dc CRITICAL 10.0 The Feather12 theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all ver… wordfence
10bad8bc-ee0a-48e6-b7f9-6651a7ab3049
< 6.6
CRITICAL 10.0 The ARforms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all vers… wordfence
1081eeb1-3240-478d-8679-7bf9293b5a95
< 2.1.12
CRITICAL 10.0 An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalat… wordfence
050b6ad4-f1e4-403f-9e0e-7fc18504f661
< 5.3.9
CRITICAL 10.0 The XStore Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.3.8 due to insuf… wordfence
fc085413-db43-43e3-9b60-aeb341eed4e1
< 9.0.2
CRITICAL 9.9 The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL… wordfence
f7fc91cc-e529-4362-8269-bf7ee0766e1e
< 4.6.13
CRITICAL 9.9 The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Tw… wordfence
f600361c-cf7a-498c-aa3d-beeb28d27101
< 1.5.67
CRITICAL 9.9 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file upl… wordfence
← Prev 1 2 3 4 5 6 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top