πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 38 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
af37f301-d97f-47d3-b6a8-88cb41344541
< 5.4.4
CRITICAL 9.8 Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication b… wordfence
af008739-3b75-4e79-ac4a-3829986b7bf0 CRITICAL 9.8 The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Privileg… wordfence
aefbebce-9433-455d-b27c-93088b0c8494
< 1.24
CRITICAL 9.8 The LeadSnap plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.23 via deser… wordfence
ae50aa5d-95e3-4650-9dbf-118b4ba3abda
< 9.644
CRITICAL 9.8 The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file typ… wordfence
ae4d47b3-59c3-46d1-80c2-d11c98fb9b1e CRITICAL 9.8 The Digital Lottery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
ae46be82-570f-4172-9c3f-746b894b84b9
< 3.4.29
CRITICAL 9.8 The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in… wordfence
ae12f71d-0f53-4942-83a7-856633e665ca CRITICAL 9.8 The Plg Novana plugin for WordPress is vulnerable to generic SQL Injection via the β€˜id’ parameter in all versions du… wordfence
ae07ca12-e827-43f9-8cbb-275b9abbd4c3 CRITICAL 9.8 The WP Query Console plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1… wordfence
ae07af10-e5fc-4f28-a343-f56c0e2bc324 CRITICAL 9.8 The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1… wordfence
add12281-7c2b-4b79-a744-36e9fd923611 CRITICAL 9.8 The SSV MailChimp plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.5. Th… wordfence
adb4644c-6ef6-4899-b0f1-2629ffacd19c
< 1.6.5
CRITICAL 9.8 The Gmedia Photo Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… wordfence
ad4acbcb-5044-4752-9db0-74bd6f99a963
< 5.0.5
CRITICAL 9.8 The Dokan Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.4. Th… wordfence
ad4878fb-dd0f-473b-9887-d993a89fedd2
< 4.3.8
CRITICAL 9.8 The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it i… wordfence
ad39d797-9230-41d9-a335-864845b56aa0
< 16.7
CRITICAL 9.8 The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p… wordfence
ad0d60f2-6354-4c2c-aaab-23fc9b8065fe CRITICAL 9.8 The HelpGent plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.4 via dese… wordfence
acebc874-5853-405c-adb3-c6582d8c5e42
< 3.3.2
CRITICAL 9.8 The Gutenberg Blocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.3.1.… wordfence
ace7ab05-799a-412c-8c0b-3429852f0263 CRITICAL 9.8 The Service Finder Bookings plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includ… wordfence
ac53af7e-0c50-413c-90de-0d50d5c17463
< 2.5.2
CRITICAL 9.8 The Tastyc theme for WordPress is vulnerable to Local File Inclusion in versions up to 2.5.2. This makes it possible for… wordfence
ac1f9d9c-4d4e-4036-95b1-50d09b5cac7c CRITICAL 9.8 The ThisWay Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the uplo… wordfence
abef988c-1fd2-45dc-8eac-447b0baad5aa
< 1.1.7
CRITICAL 9.8 The Mags theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.6. This makes i… wordfence
abe73ecd-1325-4d6d-8545-d27f6116ca43
< 1.2.9
CRITICAL 9.8 The Realteo - Real Estate Plugin by Purethemes plugin for WordPress, used by the Findeo Theme, is vulnerable to authenti… wordfence
abdd6aaa-830e-4a79-acfb-93dc4a26f599
< 2.0.15
CRITICAL 9.8 The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Remote Code Execution in ve… wordfence
abcc1ed6-1871-4e8c-9469-c44dbfca5a17 CRITICAL 9.8 The WP MLM SOFTWARE PLUGIN plugin for WordPress is vulnerable to privilege in all versions up to, and including, 4.0. Th… wordfence
ab9a5d89-16be-4dc7-9361-2b1be2324239
< 2.14.15.1
CRITICAL 9.8 The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before usi… wordfence
ab721099-677d-48f4-83ba-f4c409374e80
< 1.6.9
CRITICAL 9.8 The Accounting for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includi… wordfence
← Prev 35 36 37 38 39 40 41 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top