🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 32 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
be2ba063-140e-4c92-a57d-79f366631b3d CRITICAL 9.8 The Login with Salesforce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includi… wordfence
be1ab218-37bd-407a-8cb9-66f761849c21
< 3.1.2
CRITICAL 9.8 The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This i… wordfence
be0a6471-a78e-4fab-8ef5-93d16859bff4
< 4.4
CRITICAL 9.8 The WooCommerce Dropshipping Premium plugin for WordPress is vulnerable to SQL Injection via an unauthenticated REST end… wordfence
bd9e5654-387e-4fc3-a6eb-2eface298a9c
< 3.5.3
CRITICAL 9.8 The Amazon Product in a Post plugin for WordPress is vulnerable to generic SQL Injection via the ‘appip-cache-id’ pa… wordfence
bd7ee2d7-4588-4cb9-86ca-0daef421dd86 CRITICAL 9.8 The Hungred Post Thumbnail plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
bd332f49-5aa9-4207-89db-84692a6430e0
< 0.9.2.6
CRITICAL 9.8 The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in… wordfence
bd2ad909-a254-461d-a24f-e9803353bae4 CRITICAL 9.8 The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to privilege escalation via account … wordfence
bcd7932d-8298-43d2-bc03-932e551a2ec6 CRITICAL 9.8 The WP Dropbox Dropins plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including… wordfence
bcbbbd31-3205-4466-96f5-f9cd7e7cf083 CRITICAL 9.8 The CouponXxL theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.0.0. Thi… wordfence
bcb756d0-425e-48ae-bd7f-ec9404679aea
< 3.0.8
CRITICAL 9.8 The Feedweb plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in versions up to, and includ… wordfence
bca8b173-8e7c-41ad-9316-b38cc2ce0e66
< 1.4.0
CRITICAL 9.8 The WP Pipes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.33 due to insuffic… wordfence
bca0bc1d-c373-4ccf-928e-14f3bd4bc53c
< 2.2.4
CRITICAL 9.8 The Healsoul theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.3. This mak… wordfence
bc7e6844-23e2-4523-8261-21d4cba87db3
< 1.0.2
CRITICAL 9.8 The Theme per user plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 1.0.2 (exclusive) vi… wordfence
bc72fc26-c291-4e57-8038-babaa51c1b73 CRITICAL 9.8 The Matix Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privile… wordfence
bc656765-1eac-4a96-99e9-c22d64984923 CRITICAL 9.8 The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and includ… wordfence
bc3efc42-7cf5-4dcd-9653-891deaae19c3
< 7.0.5
CRITICAL 9.8 A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo… wordfence
bbeb32a8-5acf-4a68-859d-98652e8ff5d1
< 4.0
CRITICAL 9.8 The Email Before Download plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, … wordfence
bbd1e68f-1f84-40d6-9ecd-34280c3c5099
< 1.8.7
CRITICAL 9.8 The Yet Another Stars Rating plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… wordfence
bbcd1f31-4952-4c96-9080-804fc7d70c28 CRITICAL 9.8 The QRcode Login for WeChat plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includ… wordfence
bbc2a1f7-4c3c-4f37-a187-572f40e9b792
< 13.1.5
CRITICAL 9.8 The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t… wordfence
bbaac6b6-0871-4745-b981-55d7e9219467
< 1.2.1
CRITICAL 9.8 The Rapyd Payment Extension for WooCommerce theme for WordPress is vulnerable to PHP Object Injection in versions up to,… wordfence
bba4f30f-fc21-4387-a29e-4e4a115d7c3c
< 21.2.8
CRITICAL 9.8 The Apocalypse Meow plugin for WordPress is vulnerable to Authentication Bypass in versions 21.1.3 - 21.2.7. This is due… wordfence
bb979c91-6795-4365-a61b-2cf67a9c8223 CRITICAL 9.8 The thecotton theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the up… wordfence
bb8232cd-4fd5-4e0f-90d0-91e5eb7e70c8
< 1.2.1
CRITICAL 9.8 SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to ex… wordfence
bb6cd3a6-565e-4acf-82f0-25e85f0678bb CRITICAL 9.8 The User Control plugin for WordPress is vulnerable to generic SQL Injection via the 'users' parameter in versions up to… wordfence
← Prev 29 30 31 32 33 34 35 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top