🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 40 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a7b1871d-9d26-4bdc-bd20-0535143902d4
< 2.3
CRITICAL 9.8 The LWS Affiliation plugin for WordPress is vulnerable to Remote/Local File Inclusion in versions up to, and including, … wordfence
a79bc789-ee03-4b7b-9835-5e20a4a70714 CRITICAL 9.8 The Simen theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6. This makes it… wordfence
a76077c6-700a-4d21-a930-b0d6455d959c
< 3.0.5
CRITICAL 9.8 The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'w… wordfence
a71a9aa0-ffe3-418d-ad18-285773ee01c1 CRITICAL 9.8 The Delete Comments By Status plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… wordfence
a71a1a7b-6299-44c5-b686-65f214986c27
< 1.3.8
CRITICAL 9.8 The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.7… wordfence
a6f362c1-fe64-4be1-9713-14c0561a59ce
< 3.3.2
CRITICAL 9.8 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due… wordfence
a6d59ed7-a25e-4b96-a8de-9364aafdf72a CRITICAL 9.8 The Do That Task plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all… wordfence
a6d474cb-36ca-4a99-82de-2e154b3ae6ac
< 2.0.22
CRITICAL 9.8 The Grow by Tradedoubler – Advertiser Plugin for WooCommerce plugin for WordPress is vulnerable to Local File Inclusio… wordfence
a6bf60cc-4a07-4d5d-bff3-20d0115a5bd3
< 1.8.20
CRITICAL 9.8 The Gravityforms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via th… wordfence
a69236d1-2164-4702-96e3-abd80fb5ffbb
< 1.2.0
CRITICAL 9.8 The Api2Cart Bridge Connector plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includi… wordfence
a672c18b-1426-49fd-9590-eab8204afd5f
< 7.11.18
CRITICAL 9.8 In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize… wordfence
a636e865-9556-4afb-8726-4537a160f379
< 1.8.7
CRITICAL 9.8 The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin… wordfence
a6213e09-8a97-44cf-85ef-83179d79206c
< 4.0.5
CRITICAL 9.8 The LeagueManager plugin for WordPress is vulnerable to SQL Injection via the ‘match_id’ and 'league_id' parameters … wordfence
a61cce43-0df7-4ca9-8897-24c7d131b505
< 1.0.3
CRITICAL 9.8 The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and … wordfence
a6196b07-a2fc-45ac-8700-a1ce2713a960
< 1.3.2
CRITICAL 9.8 WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attack… wordfence
a60a9c14-d14e-469a-9cc5-681ca25db37c CRITICAL 9.8 The Easy CSV Importer BETA plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
a5f24902-1336-4fcd-b42d-e29526e61b71 CRITICAL 9.8 The Answer My Question plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in the 'modal.… wordfence
a5e45e96-3cfb-42a9-b8b7-519489bc03ad
< 4.29.5
CRITICAL 9.8 Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for Wor… wordfence
a5c290a1-b58a-4b5c-8112-076d5b17d940
< 1.2.5
CRITICAL 9.8 Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remot… wordfence
a5b7538f-891a-423f-97d1-b0212efcdb98
< 4.2.153
CRITICAL 9.8 An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almos… wordfence
a597d36c-72ce-44f0-af7b-2b9aad46957c CRITICAL 9.8 The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does no… wordfence
a57b2afa-b943-419f-9819-d7b6835c4d10 CRITICAL 9.8 The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p… wordfence
a5763e3b-01b3-4541-8fef-80fcb7e7e88e
< 2.6.7
CRITICAL 9.8 The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authen… wordfence
a5706025-962f-47e2-8d1d-16bafd937c92 CRITICAL 9.8 The Amoveo Multipurpose Wordpress Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type v… wordfence
a56d5a2f-ae13-4523-bc4a-17bb2fb4c6f0
< 3.1
CRITICAL 9.8 The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /i… wordfence
← Prev 37 38 39 40 41 42 43 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top