🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 33 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bf88e79b-262e-4fee-9cef-85d96d300972
< 2.2.0021
CRITICAL 9.8 The BePro Listings plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads in versions up to, and i… — wordfence
bf6b7d8d-fb13-4eb4-b0b4-d0a10ad2a21e
< 2.4.2.4
CRITICAL 9.8 The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposur… — wordfence
bf43d81f-2d34-4343-8b2a-e3288b1e21c5
< 12.40
CRITICAL 9.8 The DZS Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 12.39… — wordfence
bf2a57fa-28f8-4fd0-814b-a4c9ae77817a
< 2.3.2
CRITICAL 9.8 The VR Calendar plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.2.2 via … — wordfence
bf203cb9-db7c-4794-b9b7-c054fe7fc0d2 CRITICAL 9.8 The Fish House theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.7 via des… — wordfence
bf037e4a-2dd7-4296-b86b-635901d2d68f
< 3.8.4
CRITICAL 9.8 The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ… — wordfence
bec7d613-b1cd-4a4e-bbd9-62bca3a864a2
< 5.7.0
CRITICAL 9.8 The WPJobBoard plugin for WordPress is vulnerable to SQL Injections via the 'type' and 'category' parameters in versions… — wordfence
bec50640-a550-49a8-baf6-2dd53995f90b CRITICAL 9.8 The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validatio… — wordfence
be97e1ca-6c9c-4641-ba7c-bbb14a58d99e
< 4.2.1
CRITICAL 9.8 The rtMedia for WordPress, BuddyPress and bbPress for WordPress is vulnerable to Direct file access in versions up to, a… — wordfence
be8afa0c-af65-46d7-af07-de67353eddb5
< 1.2.4
CRITICAL 9.8 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Privilege Escalation i… — wordfence
be2c1555-4616-4759-bd9b-12f8b3c3a3d4
< 1.2.1
CRITICAL 9.8 The "Swape - App Showcase & App Store WordPress Theme" theme for WordPress is vulnerable to authorization bypass due to … — wordfence
be2ba063-140e-4c92-a57d-79f366631b3d CRITICAL 9.8 The Login with Salesforce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includi… — wordfence
be1ab218-37bd-407a-8cb9-66f761849c21
< 3.1.2
CRITICAL 9.8 The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This i… — wordfence
be0a6471-a78e-4fab-8ef5-93d16859bff4
< 4.4
CRITICAL 9.8 The WooCommerce Dropshipping Premium plugin for WordPress is vulnerable to SQL Injection via an unauthenticated REST end… — wordfence
bd9e5654-387e-4fc3-a6eb-2eface298a9c
< 3.5.3
CRITICAL 9.8 The Amazon Product in a Post plugin for WordPress is vulnerable to generic SQL Injection via the ‘appip-cache-id’ pa… — wordfence
bd7ee2d7-4588-4cb9-86ca-0daef421dd86 CRITICAL 9.8 The Hungred Post Thumbnail plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… — wordfence
bd332f49-5aa9-4207-89db-84692a6430e0
< 0.9.2.6
CRITICAL 9.8 The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in… — wordfence
bd2ad909-a254-461d-a24f-e9803353bae4 CRITICAL 9.8 The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to privilege escalation via account … — wordfence
bcd7932d-8298-43d2-bc03-932e551a2ec6 CRITICAL 9.8 The WP Dropbox Dropins plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including… — wordfence
bcbbbd31-3205-4466-96f5-f9cd7e7cf083 CRITICAL 9.8 The CouponXxL theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.0.0. Thi… — wordfence
bcb756d0-425e-48ae-bd7f-ec9404679aea
< 3.0.8
CRITICAL 9.8 The Feedweb plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in versions up to, and includ… — wordfence
bca8b173-8e7c-41ad-9316-b38cc2ce0e66
< 1.4.0
CRITICAL 9.8 The WP Pipes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.33 due to insuffic… — wordfence
bca0bc1d-c373-4ccf-928e-14f3bd4bc53c
< 2.2.4
CRITICAL 9.8 The Healsoul theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.3. This mak… — wordfence
bc7fab0a-78bc-4ca8-86f9-19785b00ba65 CRITICAL 9.8 The Embed HTML5 Game plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1… — wordfence
bc7e6844-23e2-4523-8261-21d4cba87db3
< 1.0.2
CRITICAL 9.8 The Theme per user plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 1.0.2 (exclusive) vi… — wordfence
← Prev 30 31 32 33 34 35 36 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top