πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 38 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b39f4467-4764-4850-bdcc-b359a6544b42
< 3.37.15
CRITICAL 9.8 LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution. — wordfence
b352b2e4-8d72-4ebd-8dcd-8e2740759f3e CRITICAL 9.8 The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is b… — wordfence
b3451ed9-9a9a-443f-b1ce-dcd07bd3e6ce CRITICAL 9.8 The WP MLM SOFTWARE PLUGIN plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… — wordfence
b343269f-35f2-4cba-b539-3a4d8fd4baf4
< 1.2.0
CRITICAL 9.8 The ShopMonitor.io – Automated Checkout & Form Monitoring plugin for WordPress is vulnerable to privilege escalation v… — wordfence
b2ea5e77-335a-4f40-9a04-9e1d4f3e1017 CRITICAL 9.8 The WP images upload on piclect plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and i… — wordfence
b2c03142-be30-4173-a140-14d73a16dd2b
< 5.0.2
CRITICAL 9.8 The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in … — wordfence
b29dcd7a-a0bc-4983-85ba-6ebf2c405ceb
< 8.1.5
CRITICAL 9.8 The Quiz and Survey Master plugin for WordPress is vulnerable to SQL Injection via the 'question_ids_[XX]' cookie in ver… — wordfence
b299a932-8167-4547-845b-637c4971360d
< 3.4.13
CRITICAL 9.8 The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Paginat… — wordfence
b291ed6f-0998-40fc-a628-4df6416c9fc4
< 3.0
CRITICAL 9.8 Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppa… — wordfence
b280155e-6d07-448d-922c-4a0ea21f4992
< 1.0.4
CRITICAL 9.8 The Biometric Login for WooCommerce plugin for WordPress is vulnerable to privilege escalation in versions up to, and in… — wordfence
b27995b1-3321-4997-8a25-80c9488b8405
< 6.930
CRITICAL 9.8 The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does no… — wordfence
b26d61de-651c-43de-ba90-33ef170755e0 CRITICAL 9.8 Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and attendees.php code do not sanitize input, this a… — wordfence
b2143edf-5423-4e79-8638-a5b98490d292
< 3.19.3
CRITICAL 9.8 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… — wordfence
b20f94c6-4e97-4fe8-a2a5-ce825bb120d3 CRITICAL 9.8 The CiyaShop theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.18.0 via dese… — wordfence
b1e98d2d-20b1-4fff-96d4-0fb8e0d2615a CRITICAL 9.8 The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… — wordfence
b1e51951-0e4c-44f3-a11b-13c0be984a7f
< 2.7.0
CRITICAL 9.8 The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… — wordfence
b1cdd6c6-f354-48d6-9493-08c67aaef9bd CRITICAL 9.8 SQL injection vulnerability in myLDlinker.php in the myLinksDump Plugin 1.2 for WordPress allows remote attackers to exe… — wordfence
b1a29180-901d-447e-8f82-63161b9e11e0 CRITICAL 9.8 The Sayfa Sayac plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6 via… — wordfence
b1782c82-bfdb-4104-a3f5-b1a07aede555 CRITICAL 9.8 Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id v… — wordfence
b170ac00-5d5c-46ef-95f3-e98ef4528999
< 6.4.2
CRITICAL 9.8 WordPress Core is vulnerable to remote code execution via a PHP gadget in version 6.4.0 and 6.4.1. This is due to there … — wordfence
b12deaa4-246e-4502-8091-fcbe5a2eae15 CRITICAL 9.8 The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php. — wordfence
b1278291-9fef-40f5-a432-d96f4bed31fe
< 3.11
CRITICAL 9.8 The Rencontre plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.10.1. T… — wordfence
b121fdb4-93a8-400c-89c2-3195cb40e03c
< 2.0.0
CRITICAL 9.8 The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all ve… — wordfence
b113f475-3133-4ea3-9152-03bb84d79307
< 1.0.4
CRITICAL 9.8 The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3… — wordfence
b10d01ec-54ef-456b-9410-ed013343a962 CRITICAL 9.8 The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… — wordfence
← Prev 35 36 37 38 39 40 41 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top