πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 3 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
54a37c4a-44c7-47fd-8f2d-486372fb643c CRITICAL 10.0 The Viral Signup – limited opt-in with viral refferal sharing plugin for WordPress is vulnerable to SQL Injection in a… — wordfence
5432bdd1-9b56-4f74-a468-011f942bdd89 CRITICAL 10.0 The Slash WP theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all vers… — wordfence
51fd6124-4954-4827-a665-c2d94d74a512
< 1.4.1
CRITICAL 10.0 The VikRentCar plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.0 due to insuff… — wordfence
43a7f1b0-c2c0-4832-9819-22625c8b727e
< 2.5.27
CRITICAL 10.0 The HTML5 Video Player – Best WordPress Video Player Plugin and Block plugin for WordPress is vulnerable to SQL Inject… — wordfence
4143febf-92b3-42e7-9499-9ea83d7727d9
< 7.3
CRITICAL 10.0 The Chauffeur Taxi Booking System for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to miss… — wordfence
3df23ba9-337f-49ac-9d1f-6b993430a1ce CRITICAL 10.0 The Propovoice Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.0.3 due to … — wordfence
3aca0d51-6f70-4f35-873a-e23b4d7bae41 CRITICAL 10.0 The WpStickyBar – Sticky Bar, Sticky Header plugin for WordPress is vulnerable to SQL Injection via the 'banner_id' pa… — wordfence
32df7bdb-d99d-4548-8960-3fefdf635753
< 1.94
CRITICAL 10.0 The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to SQL Injection via the 'onesignal_ext… — wordfence
312a6601-c914-4661-82ff-6f8bac849442 CRITICAL 10.0 The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to ins… — wordfence
2eaa5a5c-c11f-40d0-be69-c3ec8029a819
< 2.0.0
CRITICAL 10.0 The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… — wordfence
2c4c13c9-6f43-4a4d-b825-e246bf9a1e9c
< 5.7.9
CRITICAL 10.0 The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.8 due to insu… — wordfence
25999d1f-9085-4410-b76a-3570f2517bdd
< 1.7.0
CRITICAL 10.0 The Docket (WooCommerce Collections / Wishlist / Watchlist) plugin for WordPress is vulnerable to SQL Injection in versi… — wordfence
226e772e-6973-4ff0-9a02-5be503f292c8
< 2.0.1
CRITICAL 10.0 The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… — wordfence
21da3c10-72b9-4c04-8586-dcf6dcf55852
< 7.0.1
CRITICAL 10.0 The Woocommerce OpenPos plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.4.4 due … — wordfence
20fdbe6b-45a8-41f4-8dde-35a0f9ea04a1
< 3.3.1
CRITICAL 10.0 The Easy Digital Downloads plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.12 … — wordfence
1feb3fa0-5fd9-443a-830c-cb1700ff30df
< 1.8
CRITICAL 10.0 The Layouts for Elementor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check… — wordfence
191c3c86-0704-4d3c-b7ba-22cefbdc65f1
< 3.26.7
CRITICAL 10.0 The WishList Member X plugin for WordPress is vulnerable SQL Injection in versions up to, and including, 3.25.1 due to i… — wordfence
1829b4b7-5042-4972-ad05-e9a7adbf3026
< 2.7.97
CRITICAL 10.0 Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attacke… — wordfence
1261ad29-e4c1-4385-9f41-d3f3eecbb7dc CRITICAL 10.0 The Feather12 theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all ver… — wordfence
10bad8bc-ee0a-48e6-b7f9-6651a7ab3049
< 6.6
CRITICAL 10.0 The ARforms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all vers… — wordfence
1081eeb1-3240-478d-8679-7bf9293b5a95
< 2.1.12
CRITICAL 10.0 An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalat… — wordfence
050b6ad4-f1e4-403f-9e0e-7fc18504f661
< 5.3.9
CRITICAL 10.0 The XStore Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.3.8 due to insuf… — wordfence
fc085413-db43-43e3-9b60-aeb341eed4e1
< 9.0.2
CRITICAL 9.9 The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL… — wordfence
f7fc91cc-e529-4362-8269-bf7ee0766e1e
< 4.6.13
CRITICAL 9.9 The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Tw… — wordfence
f600361c-cf7a-498c-aa3d-beeb28d27101
< 1.5.67
CRITICAL 9.9 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file upl… — wordfence
← Prev 1 2 3 4 5 6 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top