🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 39 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ab4c7656-544c-4f2f-a42f-264ac90e3b61
< 1.1.5
CRITICAL 9.8 The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.… wordfence
ab46b494-e7c5-42fd-9906-2a7a529e2794
< 2022.03.01
CRITICAL 9.8 The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using i… wordfence
ab340c65-35eb-4a85-8150-3119b46c7f35
< 6.5.8.4
CRITICAL 9.8 The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all v… wordfence
ab19f79b-0cf6-4a5d-9e7e-a248728b4566
< 1.3.1
CRITICAL 9.8 The Consulting Elementor Widgets plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i… wordfence
aab3016d-5834-4b4a-a206-0b626884b335 CRITICAL 9.8 The All in One B2B for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and inc… wordfence
aab0bb92-5474-429d-b6ff-2a7662183a27
< 9.7
CRITICAL 9.8 The Stockholm theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.6. This … wordfence
aaacd8be-448f-4020-943c-9ba442ba9730 CRITICAL 9.8 The Datasets Manager by Arttia Creative plugin for WordPress is vulnerable to arbitrary file uploads due to missing file… wordfence
aa385a1f-1623-4f0a-bb2f-d4564b8f91bf CRITICAL 9.8 The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover… wordfence
aa262ff5-2b6c-421b-b155-a75d01005534
< 2.4.1
CRITICAL 9.8 The Ultimate Store Kit – Elementor powered WooCommerce Builder, 80+ Widgets and Template Builder plugin for WordPress … wordfence
aa14909c-58f6-40f1-af50-eb1a0d2333de
< 3.1.37.14
CRITICAL 9.8 The Event Espresso Free/Lite plugin for WordPress is vulnerable to Time-Based Blind SQL Injection via the ‘recurrence_… wordfence
aa080b36-01ce-496a-9938-9715f0131e29
< 3.0.7
CRITICAL 9.8 The Canto plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.0.6 via th… wordfence
a9ddbb9c-c2c9-4e34-ac22-2afe8050e15b
< 2.1
CRITICAL 9.8 SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbit… wordfence
a9d95af5-96da-4259-98c6-e2c4c574a896
< 1.3.79
CRITICAL 9.8 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to arbitrary file uploads in all versions up… wordfence
a9c7d539-2ea7-4f72-b0d2-6082e26918ce
< 1.3.59
CRITICAL 9.8 The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is v… wordfence
a9b7a73c-6fba-4b5d-9f82-c3710cc8555d
< 4.1.1
CRITICAL 9.8 The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter be… wordfence
a96c9047-9dea-4bc7-8982-8983930f7cfa CRITICAL 9.8 The Augmented reality plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient direct access res… wordfence
a9077714-bddd-4b94-b01d-054f55f18da1 CRITICAL 9.8 The Giveaway Boost plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.… wordfence
a8e6f2fe-25f7-46e4-871e-e6770d5fb00b CRITICAL 9.8 The ZIJ KART plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. This make… wordfence
a8c6c17a-9eaa-445b-b7ec-c36e15fc5b1b CRITICAL 9.8 The WP Food ordering and Restaurant Menu plugin for WordPress is vulnerable to Local File Inclusion in versions up to, a… wordfence
a8c08878-0f9f-4203-8110-a3772eb8de63
< 1.2.1
CRITICAL 9.8 Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordP… wordfence
a8b319be-f312-4d02-840f-e2a91c16b67a
< 3.92.1
CRITICAL 9.8 The Automatic plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.92.0 due to insuf… wordfence
a882c3d9-b4c1-4743-b930-382ca1081bab
< 1.0.8
CRITICAL 9.8 The WowShipping Pro plugin for WordPress was injected with a backdoor in version 1.0.6. This is due to a supply chain co… wordfence
a85fbaff-d566-4ed2-8943-c174e0c4d2d8
< 4.2.1
CRITICAL 9.8 The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to pri… wordfence
a856a96a-68d2-462d-b523-840668980807
< 1.1
CRITICAL 9.8 The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,… wordfence
a8082c60-436d-42e3-8aa5-cd2cb8ce6355 CRITICAL 9.8 includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes. wordfence
← Prev 36 37 38 39 40 41 42 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top