πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 4 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f5ad74c5-93ba-414c-98ad-0987547f172f
< 3.2.9
CRITICAL 9.9 The Simple Download Monitor plugin for WordPress is vulnerable to authorization bypass due to missing capability checks … wordfence
f54cdad2-88db-4604-8064-fa6175176760
< 2.3.4
CRITICAL 9.9 The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode … wordfence
f3abba90-9503-484e-bc2b-c6105bec698b
< 1.1.5
CRITICAL 9.9 The CRM Perks Forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.4 due to i… wordfence
f3805936-675e-474f-a3f7-acea69bd72f0
< 2.1.12
CRITICAL 9.9 An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalatio… wordfence
f31bf9cd-fbf3-4f7a-bddd-ddd44c899710
< 2.12.0
CRITICAL 9.9 The WordPress Ad Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1… wordfence
ee6f936b-704a-486f-836b-9a1892271bfa
< 1.9.8
CRITICAL 9.9 The Woocommerce Addon by Greenshift plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.8 due to i… wordfence
ee5acf1d-e405-4aa6-8355-b5aebbbb1d1d
< 3.4.3
CRITICAL 9.9 The WPtouch plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 3.4.2. This is… wordfence
e89b40ec-1952-46e3-a91b-bd38e62f8929
< 7.2.7
CRITICAL 9.9 The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missin… wordfence
e7939401-822c-4d27-9d8c-c5680165e6a7
< 4.6.0.4
CRITICAL 9.9 The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) t… wordfence
e6e96578-d54b-4c45-91cd-f143311445ea
< 7.0.8
CRITICAL 9.9 The PayPlus Payment Gateway plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.0.7 … wordfence
e604979e-81e0-4c9a-844c-381599bf226e
< 2.0.7
CRITICAL 9.9 The Zoho Campaigns plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.6 due t… wordfence
d6ebb590-1291-45dc-818a-258143a2d9a2
< 1.7.9
CRITICAL 9.9 The Slideshow Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.8 due to… wordfence
d6eb094a-4f5a-418a-ba95-635765abfcff CRITICAL 9.9 The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_image… wordfence
d50d0e87-a4be-465b-8cc1-4b56201c9fc0 CRITICAL 9.9 The AIKit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.14.1 due to insufficie… wordfence
d4f29711-6aec-4481-a3bc-2303592bb79c
< 3.26.7
CRITICAL 9.9 The Wishlist Member plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and excluding, 3.… wordfence
d33467d4-aabd-4030-ba10-68e2460b2ed2
< 3.0.0
CRITICAL 9.9 PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, whi… wordfence
d1a14fc2-cebe-4a0e-92b0-af2a9c805401 CRITICAL 9.9 The WooCommerce Amazon Affiliates - Wordpress Plugin plugin for WordPress is vulnerable to SQL Injection in versions up … wordfence
ce3e5bc7-63e9-4c0e-ae66-c24c2b8be2da
< 1.2.6
CRITICAL 9.9 The Youzify plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.5 due to insuffici… wordfence
c8eebc67-e590-4d7f-8925-e5e5090cedf0
< 6.0.4
CRITICAL 9.9 The OSM – OpenStreetMap plugin for WordPress is vulnerable to SQL Injection via the 'tagged_filter' attribute of the '… wordfence
c7a34c76-34f0-42db-af90-b477a45b84d7 CRITICAL 9.9 The canvasio3D Light plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
c75bfba9-b25a-4966-835c-8d22736de809
< 1.9.51
CRITICAL 9.9 The UpdraftPlus WordPress Backup Plugin for WordPress is vulnerable to nonce leak which leads to authorization bypass in… wordfence
c6f4ee5d-819d-4125-8cff-acf9811e2919
< 4.0.14
CRITICAL 9.9 The Podlove Podcast Publisher plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.… wordfence
c6914c8c-50ae-482f-81cd-cbd28466f3a1
< 1.7.3
CRITICAL 9.9 The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to S… wordfence
c2054dcd-1a65-48bc-9dcf-824fa448921d CRITICAL 9.9 The User Activity Log Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.3.4 du… wordfence
c1528125-9d26-40a2-9591-4220c18cef37
< 3.11.2
CRITICAL 9.9 The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the save… wordfence
← Prev 1 2 3 4 5 6 7 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top