πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 31 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c1001b2b-395a-44ee-827e-6e57f7a50218
< 1.4.2
CRITICAL 9.8 The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due… wordfence
c0e9726f-45cc-4759-909d-3de2ae9b2334
< 0.1.0.83
CRITICAL 9.8 The InstaWP Connect plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.1.0.8… wordfence
c0b50597-18c1-4cbc-aebb-348f4d786ad9
< 3.1.2
CRITICAL 9.8 The Leopard - WordPress Offload Media plugin for WordPress is vulnerable to unauthorized modification of data that can l… wordfence
c0a617fc-da3d-4828-b027-44093dd11769 CRITICAL 9.8 The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leadi… wordfence
c099f401-4b05-4532-8e31-af1b1dea7eca
< 5.4.7
CRITICAL 9.8 The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i… wordfence
c0856920-5463-4dd3-a4fd-e56901a89b83
< 2.1.5
CRITICAL 9.8 The Import XML and RSS Feeds for WordPress is vulnerable to remote code execution in versions up to, and including, 2.1.… wordfence
c080df50-1113-484b-80ed-09515982c585
< 6.0.10
CRITICAL 9.8 The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. Thi… wordfence
c035ac71-54f9-471b-93f3-6bd6a5b86ab2
< 2.8
CRITICAL 9.8 SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin b… wordfence
bfe92082-4944-43dc-b06c-3c3d22e93213
< 1.3.1
CRITICAL 9.8 The FluentCommunity plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.15 … wordfence
bfe1d122-610a-47c1-944d-bf7352e9ff38
< 3.1.0
CRITICAL 9.8 The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads. wordfence
bfd93c33-4672-4914-b052-7bea283ef60c
< 7.0.1
CRITICAL 9.8 An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthe… wordfence
bfd3926e-cdb6-44a6-bada-cb83458ca172
< 8.0.07
CRITICAL 9.8 The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution d… wordfence
bfd1e244-27c2-4c3e-9d82-a7ffefd4eab6
< 1.5.2
CRITICAL 9.8 The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using… wordfence
bfc4863a-1b8c-4b13-9df1-18f221b40b26
< 3.17.6
CRITICAL 9.8 The Flatsome theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.17.5 via dese… wordfence
bf88e79b-262e-4fee-9cef-85d96d300972
< 2.2.0021
CRITICAL 9.8 The BePro Listings plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads in versions up to, and i… wordfence
bf6b7d8d-fb13-4eb4-b0b4-d0a10ad2a21e
< 2.4.2.4
CRITICAL 9.8 The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposur… wordfence
bf43d81f-2d34-4343-8b2a-e3288b1e21c5
< 12.40
CRITICAL 9.8 The DZS Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 12.39… wordfence
bf2a57fa-28f8-4fd0-814b-a4c9ae77817a
< 2.3.2
CRITICAL 9.8 The VR Calendar plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.2.2 via … wordfence
bf203cb9-db7c-4794-b9b7-c054fe7fc0d2 CRITICAL 9.8 The Fish House theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.7 via des… wordfence
bf037e4a-2dd7-4296-b86b-635901d2d68f
< 3.8.4
CRITICAL 9.8 The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ… wordfence
bec7d613-b1cd-4a4e-bbd9-62bca3a864a2
< 5.7.0
CRITICAL 9.8 The WPJobBoard plugin for WordPress is vulnerable to SQL Injections via the 'type' and 'category' parameters in versions… wordfence
bec50640-a550-49a8-baf6-2dd53995f90b CRITICAL 9.8 The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validatio… wordfence
be97e1ca-6c9c-4641-ba7c-bbb14a58d99e
< 4.2.1
CRITICAL 9.8 The rtMedia for WordPress, BuddyPress and bbPress for WordPress is vulnerable to Direct file access in versions up to, a… wordfence
be8afa0c-af65-46d7-af07-de67353eddb5
< 1.2.4
CRITICAL 9.8 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Privilege Escalation i… wordfence
be2c1555-4616-4759-bd9b-12f8b3c3a3d4
< 1.2.1
CRITICAL 9.8 The "Swape - App Showcase & App Store WordPress Theme" theme for WordPress is vulnerable to authorization bypass due to … wordfence
← Prev 28 29 30 31 32 33 34 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top