🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 39 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b10a4561-1724-4e98-bff2-ca5416b217dc CRITICAL 9.8 The Finalist plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all known versions due to… — wordfence
b108ba89-56c4-44a8-af61-ccd6f7f73562 CRITICAL 9.8 The AA-Team Premium SEO Pack plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin… — wordfence
b0e19fc5-5e79-4383-827d-edd16443e596
< 6.3.1
CRITICAL 9.8 The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Remote Code Execution in … — wordfence
b08198a6-10e8-44ca-a1c5-8d987d85c469
< 2.6.04
CRITICAL 9.8 The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including… — wordfence
b0603621-4521-4eb0-b4dd-e2257c133cee
< 2.6.6
CRITICAL 9.8 The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'co… — wordfence
b04a5a8e-17ec-48e7-85b8-a14bd2222583 CRITICAL 9.8 The Plugin Propagator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… — wordfence
b03b7ea8-6485-495d-b815-2b7b882a75a2
< 1.6.7
CRITICAL 9.8 The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all ve… — wordfence
b0399b60-6e40-4f35-985f-845a32f69d64 CRITICAL 9.8 The TerraClassifieds – Simple Classifieds Plugin plugin for WordPress is vulnerable to arbitrary file uploads in all v… — wordfence
b0315b53-46a1-46b4-a53e-0d914866ca50 CRITICAL 9.8 The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowe… — wordfence
b0302a75-217f-4be9-876e-10ede3e3c20d CRITICAL 9.8 The Adblocker Blocker plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… — wordfence
b027c9f9-3144-4783-b646-ee1e02cd27ef
< 1.8.8
CRITICAL 9.8 The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7… — wordfence
aff754d6-8624-4068-8e31-738f6041d3a6
< 1.2.42
CRITICAL 9.8 An issue was discovered in Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-… — wordfence
aff4f695-3c3b-48ee-8de1-674b588f332f
< 5.1.5.5
CRITICAL 9.8 The Evarisk plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upl… — wordfence
afe894b0-5e91-4aa2-bbd1-1f74274701cf CRITICAL 9.8 The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including… — wordfence
afe10c10-cace-4ce4-a813-6fda04c8d3dd
< 1.2.4
CRITICAL 9.8 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass i… — wordfence
afd48bc8-d490-4a3e-97fc-70cf008cbf66
< 3.8.1
CRITICAL 9.8 The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of … — wordfence
af90aef0-fd96-43ff-8400-09bd5cebed28
< 2.67.2
CRITICAL 9.8 The WP-EMail Plugin for WordPress is vulnerable to SQL Injection via the ‘last_emailed’ parameter in versions before… — wordfence
af7345f9-6f62-424b-b02d-c145a90508ae
< 2.2.0
CRITICAL 9.8 The WordPress Zero Spam plugin for WordPress is vulnerable to Blind SQL Injection in versions up to, and including, 2.1.… — wordfence
af7163da-79b3-45df-a33c-01367205bb6f
< 1.1.0
CRITICAL 9.8 Vulnerability in Easy2map-photos WordPress Plugin v1.0.9 allows SQL Injection via unsanitized mapTemplateName, mapName, … — wordfence
af5eb3cd-f527-4b4e-a02e-699155f27b0d
< 1.1.4
CRITICAL 9.8 The Opal Woo Custom Product Variation plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient … — wordfence
af5a58d1-946a-451b-bc8b-a397345ae89a
< 4.4.4
CRITICAL 9.8 The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to PHP Object Injection in versions before 4.4.4 vi… — wordfence
af37f301-d97f-47d3-b6a8-88cb41344541
< 5.4.4
CRITICAL 9.8 Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication b… — wordfence
af008739-3b75-4e79-ac4a-3829986b7bf0 CRITICAL 9.8 The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Privileg… — wordfence
aefbebce-9433-455d-b27c-93088b0c8494
< 1.24
CRITICAL 9.8 The LeadSnap plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.23 via deser… — wordfence
ae50aa5d-95e3-4650-9dbf-118b4ba3abda
< 9.644
CRITICAL 9.8 The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file typ… — wordfence
← Prev 36 37 38 39 40 41 42 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top