πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 36 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b3f49046-d438-4c1b-803b-dba77dc28e95
< 1.7.1
CRITICAL 9.8 The Ray Enterprise Translation plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includi… wordfence
b3eee437-e65e-461e-9350-c89f21171e3c
< 15.1
CRITICAL 9.8 The WP Symposium plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… wordfence
b3e89a1c-7606-4391-a389-fa18d0967046
< 1.10.9
CRITICAL 9.8 The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actu… wordfence
b3e45a17-cb41-41ba-ab6c-c83202f0ecfd
< 2.7.6
CRITICAL 9.8 The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due … wordfence
b3d9549d-4d75-4b6a-90e2-4d403731d78f
< 6.1.3
CRITICAL 9.8 Zotpress plugin for WordPress before 6.1.3 has SQLi in zp_get_account(). wordfence
b3cf9f38-c20e-40dc-a7a1-65b0c6ba7925
< 5.1.2
CRITICAL 9.8 The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is… wordfence
b3b9ccb1-3854-4aa6-9f03-ff7f861ecc14
< 0.8
CRITICAL 9.8 PHP remote file inclusion vulnerability in ajax/savetag.php in the Theme Tuner plugin for WordPress before 0.8 allows re… wordfence
b3ae0e08-5cdc-47ff-b094-3920d56a50f7
< 3.8.0
CRITICAL 9.8 The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusio… wordfence
b39f4467-4764-4850-bdcc-b359a6544b42
< 3.37.15
CRITICAL 9.8 LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution. wordfence
b352b2e4-8d72-4ebd-8dcd-8e2740759f3e CRITICAL 9.8 The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is b… wordfence
b3451ed9-9a9a-443f-b1ce-dcd07bd3e6ce CRITICAL 9.8 The WP MLM SOFTWARE PLUGIN plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
b2c03142-be30-4173-a140-14d73a16dd2b
< 5.0.2
CRITICAL 9.8 The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in … wordfence
b29dcd7a-a0bc-4983-85ba-6ebf2c405ceb
< 8.1.5
CRITICAL 9.8 The Quiz and Survey Master plugin for WordPress is vulnerable to SQL Injection via the 'question_ids_[XX]' cookie in ver… wordfence
b299a932-8167-4547-845b-637c4971360d
< 3.4.13
CRITICAL 9.8 The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Paginat… wordfence
b291ed6f-0998-40fc-a628-4df6416c9fc4
< 3.0
CRITICAL 9.8 Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppa… wordfence
b280155e-6d07-448d-922c-4a0ea21f4992
< 1.0.4
CRITICAL 9.8 The Biometric Login for WooCommerce plugin for WordPress is vulnerable to privilege escalation in versions up to, and in… wordfence
b27995b1-3321-4997-8a25-80c9488b8405
< 6.930
CRITICAL 9.8 The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does no… wordfence
b26d61de-651c-43de-ba90-33ef170755e0 CRITICAL 9.8 Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and attendees.php code do not sanitize input, this a… wordfence
b2143edf-5423-4e79-8638-a5b98490d292
< 3.19.3
CRITICAL 9.8 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… wordfence
b20f94c6-4e97-4fe8-a2a5-ce825bb120d3 CRITICAL 9.8 The CiyaShop theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.18.0 via dese… wordfence
b1e98d2d-20b1-4fff-96d4-0fb8e0d2615a CRITICAL 9.8 The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
b1e51951-0e4c-44f3-a11b-13c0be984a7f
< 2.7.0
CRITICAL 9.8 The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… wordfence
b1cdd6c6-f354-48d6-9493-08c67aaef9bd CRITICAL 9.8 SQL injection vulnerability in myLDlinker.php in the myLinksDump Plugin 1.2 for WordPress allows remote attackers to exe… wordfence
b1a29180-901d-447e-8f82-63161b9e11e0 CRITICAL 9.8 The Sayfa Sayac plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6 via… wordfence
b1782c82-bfdb-4104-a3f5-b1a07aede555 CRITICAL 9.8 Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id v… wordfence
← Prev 33 34 35 36 37 38 39 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top