🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 40 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ae4d47b3-59c3-46d1-80c2-d11c98fb9b1e CRITICAL 9.8 The Digital Lottery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … — wordfence
ae46be82-570f-4172-9c3f-746b894b84b9
< 3.4.29
CRITICAL 9.8 The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in… — wordfence
ae12f71d-0f53-4942-83a7-856633e665ca CRITICAL 9.8 The Plg Novana plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in all versions du… — wordfence
ae07ca12-e827-43f9-8cbb-275b9abbd4c3 CRITICAL 9.8 The WP Query Console plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1… — wordfence
ae07af10-e5fc-4f28-a343-f56c0e2bc324 CRITICAL 9.8 The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1… — wordfence
add12281-7c2b-4b79-a744-36e9fd923611 CRITICAL 9.8 The SSV MailChimp plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.5. Th… — wordfence
adb4644c-6ef6-4899-b0f1-2629ffacd19c
< 1.6.5
CRITICAL 9.8 The Gmedia Photo Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… — wordfence
ad4acbcb-5044-4752-9db0-74bd6f99a963
< 5.0.5
CRITICAL 9.8 The Dokan Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.4. Th… — wordfence
ad4878fb-dd0f-473b-9887-d993a89fedd2
< 4.3.8
CRITICAL 9.8 The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it i… — wordfence
ad39d797-9230-41d9-a335-864845b56aa0
< 16.7
CRITICAL 9.8 The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p… — wordfence
ad22cb24-e6a0-456f-afe8-88a39acd97d3
< 1.7
CRITICAL 9.8 The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6… — wordfence
ad0d60f2-6354-4c2c-aaab-23fc9b8065fe CRITICAL 9.8 The HelpGent plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.4 via dese… — wordfence
ad0a9daf-d59b-4db0-add9-dbf87fb4708e CRITICAL 9.8 The POUCO Import Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, … — wordfence
acebc874-5853-405c-adb3-c6582d8c5e42
< 3.3.2
CRITICAL 9.8 The Gutenberg Blocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.3.1.… — wordfence
ace7ab05-799a-412c-8c0b-3429852f0263 CRITICAL 9.8 The Service Finder Bookings plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includ… — wordfence
ac53af7e-0c50-413c-90de-0d50d5c17463
< 2.5.2
CRITICAL 9.8 The Tastyc theme for WordPress is vulnerable to Local File Inclusion in versions up to 2.5.2. This makes it possible for… — wordfence
ac1f9d9c-4d4e-4036-95b1-50d09b5cac7c CRITICAL 9.8 The ThisWay Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the uplo… — wordfence
ac1257a9-7c8e-43aa-b21a-93a77b456aa4
< 1.2.3
CRITICAL 9.8 The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulne… — wordfence
abef988c-1fd2-45dc-8eac-447b0baad5aa
< 1.1.7
CRITICAL 9.8 The Mags theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.6. This makes i… — wordfence
abe73ecd-1325-4d6d-8545-d27f6116ca43
< 1.2.9
CRITICAL 9.8 The Realteo - Real Estate Plugin by Purethemes plugin for WordPress, used by the Findeo Theme, is vulnerable to authenti… — wordfence
abdd6aaa-830e-4a79-acfb-93dc4a26f599
< 2.0.15
CRITICAL 9.8 The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Remote Code Execution in ve… — wordfence
abcc1ed6-1871-4e8c-9469-c44dbfca5a17 CRITICAL 9.8 The WP MLM SOFTWARE PLUGIN plugin for WordPress is vulnerable to privilege in all versions up to, and including, 4.0. Th… — wordfence
abc138f5-0bb7-4ce3-a504-89580021bedb
< 2.0.67
CRITICAL 9.8 The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.… — wordfence
ab9a5d89-16be-4dc7-9361-2b1be2324239
< 2.14.15.1
CRITICAL 9.8 The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before usi… — wordfence
ab721099-677d-48f4-83ba-f4c409374e80
< 1.6.9
CRITICAL 9.8 The Accounting for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includi… — wordfence
← Prev 37 38 39 40 41 42 43 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top