πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 34 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b8dd6008-e9b8-4a87-b1c7-0dc272850cbd CRITICAL 9.8 The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and incl… wordfence
b8cbd521-f2d4-4cf6-a50f-ed42f4d21989 CRITICAL 9.8 The PHP Shell plugin for WordPress is used for Remote Code Execution in all versions up to, and including, 1.0. This all… wordfence
b8c18081-1ee3-4072-89f1-b6eb1518916e
< 2.7.6
CRITICAL 9.8 The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the… wordfence
b8bbb54d-7607-4d19-bf2d-2d52a6de1287
< 1.1.1
CRITICAL 9.8 SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin before 1.1.1 for WordPress allows rem… wordfence
b8b443bb-4b23-48a1-9859-953b3cd84ca6
< 29.0.2
CRITICAL 9.8 The Contest Gallery Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,… wordfence
b894473b-b2ed-475b-892e-603db609f88a
< 3.4.3
CRITICAL 9.8 The JupiterX Core plugin for WordPress is vulnerable to privilege escalation due to insufficient validation in versions … wordfence
b884d3c9-7d84-44eb-9e94-b415625b479d
< 0.60
CRITICAL 9.8 The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to generic S… wordfence
b883681e-5e14-4100-989b-4776456246bf CRITICAL 9.8 The SSV Events plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.2.7. This … wordfence
b8672fd2-dc7a-4717-9d25-84180ad9b134
< 1.21.16
CRITICAL 9.8 The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFI… wordfence
b8652b40-480c-4d53-b1c8-e1dcfbd8a4a4 CRITICAL 9.8 The AREA53 Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the php.p… wordfence
b8347b4e-a5ba-49c5-9ae6-690a1a5c9aac
< 12.1
CRITICAL 9.8 The tagDiv Composer plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versi… wordfence
b829b7a1-2891-402b-a48f-a7fb1202448e
< 2.8
CRITICAL 9.8 The Shortcode Factory plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 v… wordfence
b812a0d7-99a1-4f61-b78a-78cea6a2ada1
< 4.79
CRITICAL 9.8 The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin… wordfence
b811f085-9374-41e7-a9ab-fecff0b9e19d
< 3.1.0
CRITICAL 9.8 Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_qui… wordfence
b80c2a5a-49f2-4b93-a1eb-a0be53aa921d CRITICAL 9.8 The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available… wordfence
b803ee40-733a-49bf-a134-406747541eb6
< 0.5.0
CRITICAL 9.8 The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parame… wordfence
b7f3b469-9a6c-4cc1-bb27-bd57bbae7208
< 6.8.2
CRITICAL 9.8 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to… wordfence
b7b1620e-a26b-454d-890c-37dfa90abfad CRITICAL 9.8 The CWW Portfolio theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.1. Thi… wordfence
b78eb275-bede-44f0-bf72-6931c37d78bf
< 1.3.4
CRITICAL 9.8 The TS Poll – Best Poll Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass due to a missi… wordfence
b77c3d65-23c0-4bda-afea-9cad00fc04d6
< 1.3.19
CRITICAL 9.8 The Invite Anyone plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.18 vi… wordfence
b772a695-658f-41aa-b40e-b5a91a6d01a4 CRITICAL 9.8 The Booking Calendar and Notification plugin for WordPress is vulnerable to authentication bypass in all versions up to,… wordfence
b771199e-937f-46d5-9906-4cbbbcd748cd CRITICAL 9.8 The 4ECPS Web Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
b71706a7-e101-4d50-a2da-1aeeaf07cf4b
< 7.6.25
CRITICAL 9.8 The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includi… wordfence
b71348c8-9e86-432e-b05e-96884344cef6
< 1.1.4
CRITICAL 9.8 The LogDash Activity Log plugin for WordPress is vulnerable to SQL Injection via the username parameter in all versions … wordfence
b70f5416-06e0-4b6f-b61d-b7c23575a171
< 3.9.1
CRITICAL 9.8 The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues. wordfence
← Prev 31 32 33 34 35 36 37 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top