🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 37 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b170ac00-5d5c-46ef-95f3-e98ef4528999
< 6.4.2
CRITICAL 9.8 WordPress Core is vulnerable to remote code execution via a PHP gadget in version 6.4.0 and 6.4.1. This is due to there … wordfence
b12deaa4-246e-4502-8091-fcbe5a2eae15 CRITICAL 9.8 The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php. wordfence
b1278291-9fef-40f5-a432-d96f4bed31fe
< 3.11
CRITICAL 9.8 The Rencontre plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.10.1. T… wordfence
b121fdb4-93a8-400c-89c2-3195cb40e03c
< 2.0.0
CRITICAL 9.8 The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all ve… wordfence
b113f475-3133-4ea3-9152-03bb84d79307
< 1.0.4
CRITICAL 9.8 The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3… wordfence
b10d01ec-54ef-456b-9410-ed013343a962 CRITICAL 9.8 The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… wordfence
b10a4561-1724-4e98-bff2-ca5416b217dc CRITICAL 9.8 The Finalist plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all known versions due to… wordfence
b108ba89-56c4-44a8-af61-ccd6f7f73562 CRITICAL 9.8 The AA-Team Premium SEO Pack plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin… wordfence
b08198a6-10e8-44ca-a1c5-8d987d85c469
< 2.6.04
CRITICAL 9.8 The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including… wordfence
b0603621-4521-4eb0-b4dd-e2257c133cee
< 2.6.6
CRITICAL 9.8 The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'co… wordfence
b04a5a8e-17ec-48e7-85b8-a14bd2222583 CRITICAL 9.8 The Plugin Propagator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
b0399b60-6e40-4f35-985f-845a32f69d64 CRITICAL 9.8 The TerraClassifieds – Simple Classifieds Plugin plugin for WordPress is vulnerable to arbitrary file uploads in all v… wordfence
b0315b53-46a1-46b4-a53e-0d914866ca50 CRITICAL 9.8 The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowe… wordfence
b0302a75-217f-4be9-876e-10ede3e3c20d CRITICAL 9.8 The Adblocker Blocker plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
b027c9f9-3144-4783-b646-ee1e02cd27ef
< 1.8.8
CRITICAL 9.8 The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7… wordfence
aff754d6-8624-4068-8e31-738f6041d3a6
< 1.2.42
CRITICAL 9.8 An issue was discovered in Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-… wordfence
aff4f695-3c3b-48ee-8de1-674b588f332f
< 5.1.5.5
CRITICAL 9.8 The Evarisk plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upl… wordfence
afe894b0-5e91-4aa2-bbd1-1f74274701cf CRITICAL 9.8 The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including… wordfence
afe10c10-cace-4ce4-a813-6fda04c8d3dd
< 1.2.4
CRITICAL 9.8 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass i… wordfence
afd48bc8-d490-4a3e-97fc-70cf008cbf66
< 3.8.1
CRITICAL 9.8 The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of … wordfence
af90aef0-fd96-43ff-8400-09bd5cebed28
< 2.67.2
CRITICAL 9.8 The WP-EMail Plugin for WordPress is vulnerable to SQL Injection via the ‘last_emailed’ parameter in versions before… wordfence
af7345f9-6f62-424b-b02d-c145a90508ae
< 2.2.0
CRITICAL 9.8 The WordPress Zero Spam plugin for WordPress is vulnerable to Blind SQL Injection in versions up to, and including, 2.1.… wordfence
af7163da-79b3-45df-a33c-01367205bb6f
< 1.1.0
CRITICAL 9.8 Vulnerability in Easy2map-photos WordPress Plugin v1.0.9 allows SQL Injection via unsanitized mapTemplateName, mapName, … wordfence
af5eb3cd-f527-4b4e-a02e-699155f27b0d
< 1.1.4
CRITICAL 9.8 The Opal Woo Custom Product Variation plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient … wordfence
af5a58d1-946a-451b-bc8b-a397345ae89a
< 4.4.4
CRITICAL 9.8 The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to PHP Object Injection in versions before 4.4.4 vi… wordfence
← Prev 34 35 36 37 38 39 40 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top