🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 35 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b6efe739-713b-4620-b78f-a8ec7b164cd1 CRITICAL 9.8 The Support Ticket plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.… wordfence
b6ee571d-8db6-4e21-9a62-44e562b9a5fc
< 2.0.16
CRITICAL 9.8 wordfence
b6cab377-0a8a-45d2-a966-4c7f100b9409 CRITICAL 9.8 The Portfolio Slideshow Pro plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in al… wordfence
b6c69a25-8986-4976-8753-ce8e5be311e2
< 2.0.6
CRITICAL 9.8 The Absolute Privacy plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 2.0.5… wordfence
b6c5cc05-b147-46f6-aaa9-4c82aae1b544
< 1.0.1
CRITICAL 9.8 The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, an… wordfence
b6b43503-e6f0-4097-9e41-eaae7011b17b
< 1.8
CRITICAL 9.8 The Nexos - Real Estate WordPress Theme theme for WordPress is vulnerable to generic SQL Injection via the ‘search_ord… wordfence
b69c86f4-d81d-4e14-baff-3402008bb9c6
< 4.19.1
CRITICAL 9.8 The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions … wordfence
b65cdbe0-e258-4bb5-9a36-cbf57b75ce77 CRITICAL 9.8 The Custom Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
b5ed8a39-50b0-4acf-9054-ba389c49f345
< 8.4
CRITICAL 9.8 The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8… wordfence
b5a1baaa-d593-4559-953c-9393bde8d711
< 3.11
CRITICAL 9.8 The Ajax Search Lite plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.10 … wordfence
b55567e9-24e6-4738-b7f7-b95b541e6067
< 1.8.4.1
CRITICAL 9.8 The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the news… wordfence
b550a140-0bdc-4840-806a-3eaceee7e42f
< 2.6.1
CRITICAL 9.8 The JobSearch WP Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi… wordfence
b53066d3-2ff3-4460-896a-facd77455914
< 4.7.6
CRITICAL 9.8 The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versio… wordfence
b52fe73f-3e90-40d6-bccc-d535c3b426d0
< 5.2.1
CRITICAL 9.8 The Essential Real Estate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5… wordfence
b52ae51d-7b9a-4047-82bf-723ea87d2375
< 1.5.3
CRITICAL 9.8 The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 vi… wordfence
b5165f60-6515-4a2c-a124-cc88155eaf01
< 4.24.14
CRITICAL 9.8 The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi… wordfence
b5136409-d843-4774-afe7-211a23f65da9
< 1.4.7.1
CRITICAL 9.8 The Duplicator WordPress Plugin is vulnerable to Unauthenticated Backup Download in versions up to, and including, 1.4.7… wordfence
b50d6fd0-3698-4e16-aa76-0344306bc705
< 1.0.9
CRITICAL 9.8 The WP Sessions Time Monitoring Full Automatic plugin for WordPress is vulnerable to SQL Injection via request parameter… wordfence
b5023e07-9976-44f3-81de-2eb4ba86b0ca
< 3.3.21.2
CRITICAL 9.8 The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page. wordfence
b4cd5c42-bba2-4900-b450-a575c0007402
< 2.5.8
CRITICAL 9.8 The Easy Digital Downloads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … wordfence
b4b3b4a4-9a56-49b8-b3d3-7e50954b4487
< 7.2.1
CRITICAL 9.8 The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress all… wordfence
b46cd71f-046a-45b8-be8d-4a71e97586b4
< 3.6.3
CRITICAL 9.8 The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to arbitrary file deletion in all ver… wordfence
b412f60f-61ea-47b1-a3ef-17275f7951df
< 5.4.5
CRITICAL 9.8 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to,… wordfence
b4080bb7-9197-4c93-bcb1-cf7b5833771a CRITICAL 9.8 The Dean's FCKEditor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… wordfence
b3f7a88c-a09b-46ac-b345-139c2d20a3d2
< 4.5.14.2
CRITICAL 9.8 Duplicator and Duplicator Pro for WordPress are vulnerable to Sensitive Information Exposure in various versions. This m… wordfence
← Prev 32 33 34 35 36 37 38 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top