πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 33 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bb6182e8-ba5c-4873-aa18-45a79191c8c5
< 3.7.23
CRITICAL 9.8 WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading t… wordfence
bb3f2af4-b5cc-43c0-8425-224281300d66 CRITICAL 9.8 The Grand Restaurant WordPress theme for WordPress is vulnerable to PHP Object Injection in versions up to, and includin… wordfence
bb00eae9-645d-4827-b691-2408fd24aa75
< 1.22.21
CRITICAL 9.8 The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to authentication bypass in all versions up… wordfence
bae5f22d-5085-4230-a7fc-5db85aa6fbdb
< 67.2.0
CRITICAL 9.8 The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing … wordfence
bac8c35b-2afa-4347-b86e-2f16db19a4d3
< 5.0.13
CRITICAL 9.8 The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. Thi… wordfence
babbe506-3abd-462a-b5b8-5979696eb6e6
< 20230914
CRITICAL 9.8 The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… wordfence
bab67a5c-3390-4423-8fa9-b5ffbc98324d
< 1.3.84
CRITICAL 9.8 The Ultimate Member plugin for WordPress is vulnerable to Executing Arbitrary WordPress Shortcodes in versions up to, an… wordfence
baab579f-2d77-4dbe-979a-54956dfdcb77
< 3.2.5
CRITICAL 9.8 The Zephyr Project Manager plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to,… wordfence
ba8d377f-d216-40e4-97f2-ed3eac0ec33e
< 1.6.4
CRITICAL 9.8 The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ss… wordfence
ba84711f-bdbe-46d3-a9a3-cc2b1dcefd1a
< 2.0.2
CRITICAL 9.8 The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin… wordfence
ba6d8be6-e7a6-4275-b5f1-86e2ea85ff76
< 3.9.51
CRITICAL 9.8 The Locatoraid Store Locator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… wordfence
ba502aac-13f7-40e2-9672-bf26a0fefef7
< 5.3.9
CRITICAL 9.8 The XStore Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.3.8 v… wordfence
ba1a25e9-bac3-4f76-8324-3035be94da4c
< 1.0.41
CRITICAL 9.8 The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPres… wordfence
ba18bd0c-ba6c-4f98-ac29-660a79affa6c
< 1.5.2
CRITICAL 9.8 The Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce plugin for WordPres… wordfence
ba1004c7-52f4-4fea-b820-dd11b2264e15 CRITICAL 9.8 The MoneyTheme theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u… wordfence
b9d9d05f-0de7-473f-ae33-a97967c6fcf7 CRITICAL 9.8 The PDF-Rechnungsverwaltung plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including,… wordfence
b994bb62-436f-4edc-8891-281483428ac0 CRITICAL 9.8 The IWS - Geo Form Fields plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to… wordfence
b98179c3-8b32-4d75-9f3f-2367215a740b
< 1.7.8
CRITICAL 9.8 The Pie Register - Social Sites Login (Add on) plugin for WordPress is vulnerable to authentication bypass in versions u… wordfence
b97b1c86-22a4-462b-9140-55139cf02c7a
< 1.9.6.1
CRITICAL 9.8 The Bricks theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.6. This … wordfence
b97805de-1b47-4c9f-baae-2e37c1b78570 CRITICAL 9.8 The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_i… wordfence
b9371b37-53c5-4a4f-a500-c6d58d4d3c5a
< 84.4
CRITICAL 9.8 The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… wordfence
b9119e20-8615-4447-9eb8-4a0259319eb4 CRITICAL 9.8 The WordPress Events Calendar Registration & Tickets plugin for WordPress is vulnerable to PHP Object Injection in versi… wordfence
b905b8ec-d13d-4455-9c5f-61aaa09d75ba
< 1.3.4.3
CRITICAL 9.8 The HUSKY – Products Filter for WooCommerce (formerly WOOF) plugin for WordPress is vulnerable to generic SQL Injectio… wordfence
b8eeeed6-bb8c-47d3-afa5-84eb7ed2c971
< 1.6
CRITICAL 9.8 Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-… wordfence
b8eb3aa9-fe60-48b6-aa24-7873dd68b47e
< 3.16.4
CRITICAL 9.8 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… wordfence
← Prev 30 31 32 33 34 35 36 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top