🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 36 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b8672fd2-dc7a-4717-9d25-84180ad9b134
< 1.21.16
CRITICAL 9.8 The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFI… — wordfence
b8652b40-480c-4d53-b1c8-e1dcfbd8a4a4 CRITICAL 9.8 The AREA53 Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the php.p… — wordfence
b8347b4e-a5ba-49c5-9ae6-690a1a5c9aac
< 12.1
CRITICAL 9.8 The tagDiv Composer plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versi… — wordfence
b829b7a1-2891-402b-a48f-a7fb1202448e
< 2.8
CRITICAL 9.8 The Shortcode Factory plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 v… — wordfence
b812a0d7-99a1-4f61-b78a-78cea6a2ada1
< 4.79
CRITICAL 9.8 The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin… — wordfence
b811f085-9374-41e7-a9ab-fecff0b9e19d
< 3.1.0
CRITICAL 9.8 Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_qui… — wordfence
b80c2a5a-49f2-4b93-a1eb-a0be53aa921d CRITICAL 9.8 The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available… — wordfence
b803ee40-733a-49bf-a134-406747541eb6
< 0.5.0
CRITICAL 9.8 The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parame… — wordfence
b7f3b469-9a6c-4cc1-bb27-bd57bbae7208
< 6.8.2
CRITICAL 9.8 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to… — wordfence
b7b1620e-a26b-454d-890c-37dfa90abfad CRITICAL 9.8 The CWW Portfolio theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.1. Thi… — wordfence
b78eb275-bede-44f0-bf72-6931c37d78bf
< 1.3.4
CRITICAL 9.8 The TS Poll – Best Poll Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass due to a missi… — wordfence
b77c3d65-23c0-4bda-afea-9cad00fc04d6
< 1.3.19
CRITICAL 9.8 The Invite Anyone plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.18 vi… — wordfence
b772a695-658f-41aa-b40e-b5a91a6d01a4 CRITICAL 9.8 The Booking Calendar and Notification plugin for WordPress is vulnerable to authentication bypass in all versions up to,… — wordfence
b771199e-937f-46d5-9906-4cbbbcd748cd CRITICAL 9.8 The 4ECPS Web Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … — wordfence
b71706a7-e101-4d50-a2da-1aeeaf07cf4b
< 7.6.25
CRITICAL 9.8 The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includi… — wordfence
b71348c8-9e86-432e-b05e-96884344cef6
< 1.1.4
CRITICAL 9.8 The LogDash Activity Log plugin for WordPress is vulnerable to SQL Injection via the username parameter in all versions … — wordfence
b70f5416-06e0-4b6f-b61d-b7c23575a171
< 3.9.1
CRITICAL 9.8 The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues. — wordfence
b6efe739-713b-4620-b78f-a8ec7b164cd1 CRITICAL 9.8 The Support Ticket plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.… — wordfence
b6ee571d-8db6-4e21-9a62-44e562b9a5fc
< 2.0.16
CRITICAL 9.8 … — wordfence
b6cab377-0a8a-45d2-a966-4c7f100b9409 CRITICAL 9.8 The Portfolio Slideshow Pro plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in al… — wordfence
b6c69a25-8986-4976-8753-ce8e5be311e2
< 2.0.6
CRITICAL 9.8 The Absolute Privacy plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 2.0.5… — wordfence
b6c5cc05-b147-46f6-aaa9-4c82aae1b544
< 1.0.1
CRITICAL 9.8 The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, an… — wordfence
b6b43503-e6f0-4097-9e41-eaae7011b17b
< 1.8
CRITICAL 9.8 The Nexos - Real Estate WordPress Theme theme for WordPress is vulnerable to generic SQL Injection via the ‘search_ord… — wordfence
b69c86f4-d81d-4e14-baff-3402008bb9c6
< 4.19.1
CRITICAL 9.8 The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions … — wordfence
b65cdbe0-e258-4bb5-9a36-cbf57b75ce77 CRITICAL 9.8 The Custom Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… — wordfence
← Prev 33 34 35 36 37 38 39 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top