πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 35 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ba1a25e9-bac3-4f76-8324-3035be94da4c
< 1.0.41
CRITICAL 9.8 The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPres… — wordfence
ba18bd0c-ba6c-4f98-ac29-660a79affa6c
< 1.5.2
CRITICAL 9.8 The Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce plugin for WordPres… — wordfence
ba1004c7-52f4-4fea-b820-dd11b2264e15 CRITICAL 9.8 The MoneyTheme theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u… — wordfence
b9f75a13-76be-45b5-8ec3-a89cbb6e0256
< 6.0.9.9
CRITICAL 9.8 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … — wordfence
b9d9d05f-0de7-473f-ae33-a97967c6fcf7 CRITICAL 9.8 The PDF-Rechnungsverwaltung plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including,… — wordfence
b9d11eb9-5e18-459f-a9d4-cccb1d593402
< 1.17.9
CRITICAL 9.8 The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted Fi… — wordfence
b994bb62-436f-4edc-8891-281483428ac0 CRITICAL 9.8 The IWS - Geo Form Fields plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to… — wordfence
b98179c3-8b32-4d75-9f3f-2367215a740b
< 1.7.8
CRITICAL 9.8 The Pie Register - Social Sites Login (Add on) plugin for WordPress is vulnerable to authentication bypass in versions u… — wordfence
b97b1c86-22a4-462b-9140-55139cf02c7a
< 1.9.6.1
CRITICAL 9.8 The Bricks theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.6. This … — wordfence
b97805de-1b47-4c9f-baae-2e37c1b78570 CRITICAL 9.8 The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_i… — wordfence
b9690fc8-cd0c-42e4-aa21-5c71243565f0 CRITICAL 9.8 The Frontegg SAML SSO plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, … — wordfence
b9371b37-53c5-4a4f-a500-c6d58d4d3c5a
< 84.4
CRITICAL 9.8 The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… — wordfence
b9119e20-8615-4447-9eb8-4a0259319eb4 CRITICAL 9.8 The WordPress Events Calendar Registration & Tickets plugin for WordPress is vulnerable to PHP Object Injection in versi… — wordfence
b905b8ec-d13d-4455-9c5f-61aaa09d75ba
< 1.3.4.3
CRITICAL 9.8 The HUSKY – Products Filter for WooCommerce (formerly WOOF) plugin for WordPress is vulnerable to generic SQL Injectio… — wordfence
b8eeeed6-bb8c-47d3-afa5-84eb7ed2c971
< 1.6
CRITICAL 9.8 Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-… — wordfence
b8eb3aa9-fe60-48b6-aa24-7873dd68b47e
< 3.16.4
CRITICAL 9.8 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… — wordfence
b8dd6008-e9b8-4a87-b1c7-0dc272850cbd CRITICAL 9.8 The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and incl… — wordfence
b8cbd521-f2d4-4cf6-a50f-ed42f4d21989 CRITICAL 9.8 The PHP Shell plugin for WordPress is used for Remote Code Execution in all versions up to, and including, 1.0. This all… — wordfence
b8c18081-1ee3-4072-89f1-b6eb1518916e
< 2.7.6
CRITICAL 9.8 The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the… — wordfence
b8bbb54d-7607-4d19-bf2d-2d52a6de1287
< 1.1.1
CRITICAL 9.8 SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin before 1.1.1 for WordPress allows rem… — wordfence
b8b443bb-4b23-48a1-9859-953b3cd84ca6
< 29.0.2
CRITICAL 9.8 The Contest Gallery Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,… — wordfence
b8a7a925-2b9e-43bc-b649-c7ec518e063c
< 0.9.2.7
CRITICAL 9.8 The Advanced Custom Fields: Extended PRO plugin for WordPress is vulnerable to Limited Code Injection in all versions up… — wordfence
b894473b-b2ed-475b-892e-603db609f88a
< 3.4.3
CRITICAL 9.8 The JupiterX Core plugin for WordPress is vulnerable to privilege escalation due to insufficient validation in versions … — wordfence
b884d3c9-7d84-44eb-9e94-b415625b479d
< 0.60
CRITICAL 9.8 The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to generic S… — wordfence
b883681e-5e14-4100-989b-4776456246bf CRITICAL 9.8 The SSV Events plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.2.7. This … — wordfence
← Prev 32 33 34 35 36 37 38 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top