πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 37 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b5ed8a39-50b0-4acf-9054-ba389c49f345
< 8.4
CRITICAL 9.8 The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8… — wordfence
b5a1baaa-d593-4559-953c-9393bde8d711
< 3.11
CRITICAL 9.8 The Ajax Search Lite plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.10 … — wordfence
b55567e9-24e6-4738-b7f7-b95b541e6067
< 1.8.4.1
CRITICAL 9.8 The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the news… — wordfence
b550a140-0bdc-4840-806a-3eaceee7e42f
< 2.6.1
CRITICAL 9.8 The JobSearch WP Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi… — wordfence
b53066d3-2ff3-4460-896a-facd77455914
< 4.7.6
CRITICAL 9.8 The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versio… — wordfence
b52fe73f-3e90-40d6-bccc-d535c3b426d0
< 5.2.1
CRITICAL 9.8 The Essential Real Estate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5… — wordfence
b52ae51d-7b9a-4047-82bf-723ea87d2375
< 1.5.3
CRITICAL 9.8 The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 vi… — wordfence
b5165f60-6515-4a2c-a124-cc88155eaf01
< 4.24.14
CRITICAL 9.8 The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi… — wordfence
b5136409-d843-4774-afe7-211a23f65da9
< 1.4.7.1
CRITICAL 9.8 The Duplicator WordPress Plugin is vulnerable to Unauthenticated Backup Download in versions up to, and including, 1.4.7… — wordfence
b50d6fd0-3698-4e16-aa76-0344306bc705
< 1.0.9
CRITICAL 9.8 The WP Sessions Time Monitoring Full Automatic plugin for WordPress is vulnerable to SQL Injection via request parameter… — wordfence
b5023e07-9976-44f3-81de-2eb4ba86b0ca
< 3.3.21.2
CRITICAL 9.8 The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page. — wordfence
b4cd5c42-bba2-4900-b450-a575c0007402
< 2.5.8
CRITICAL 9.8 The Easy Digital Downloads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … — wordfence
b4b3b4a4-9a56-49b8-b3d3-7e50954b4487
< 7.2.1
CRITICAL 9.8 The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress all… — wordfence
b46cd71f-046a-45b8-be8d-4a71e97586b4
< 3.6.3
CRITICAL 9.8 The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to arbitrary file deletion in all ver… — wordfence
b412f60f-61ea-47b1-a3ef-17275f7951df
< 5.4.5
CRITICAL 9.8 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to,… — wordfence
b4080bb7-9197-4c93-bcb1-cf7b5833771a CRITICAL 9.8 The Dean's FCKEditor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… — wordfence
b3f7a88c-a09b-46ac-b345-139c2d20a3d2
< 4.5.14.2
CRITICAL 9.8 Duplicator and Duplicator Pro for WordPress are vulnerable to Sensitive Information Exposure in various versions. This m… — wordfence
b3f49046-d438-4c1b-803b-dba77dc28e95
< 1.7.1
CRITICAL 9.8 The Ray Enterprise Translation plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includi… — wordfence
b3eee437-e65e-461e-9350-c89f21171e3c
< 15.1
CRITICAL 9.8 The WP Symposium plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… — wordfence
b3e89a1c-7606-4391-a389-fa18d0967046
< 1.10.9
CRITICAL 9.8 The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actu… — wordfence
b3e45a17-cb41-41ba-ab6c-c83202f0ecfd
< 2.7.6
CRITICAL 9.8 The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due … — wordfence
b3d9549d-4d75-4b6a-90e2-4d403731d78f
< 6.1.3
CRITICAL 9.8 Zotpress plugin for WordPress before 6.1.3 has SQLi in zp_get_account(). — wordfence
b3cf9f38-c20e-40dc-a7a1-65b0c6ba7925
< 5.1.2
CRITICAL 9.8 The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is… — wordfence
b3b9ccb1-3854-4aa6-9f03-ff7f861ecc14
< 0.8
CRITICAL 9.8 PHP remote file inclusion vulnerability in ajax/savetag.php in the Theme Tuner plugin for WordPress before 0.8 allows re… — wordfence
b3ae0e08-5cdc-47ff-b094-3920d56a50f7
< 3.8.0
CRITICAL 9.8 The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusio… — wordfence
← Prev 34 35 36 37 38 39 40 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top