🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 42 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a85fbaff-d566-4ed2-8943-c174e0c4d2d8
< 4.2.1
CRITICAL 9.8 The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to pri… — wordfence
a856a96a-68d2-462d-b523-840668980807
< 1.1
CRITICAL 9.8 The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,… — wordfence
a80f3c4c-1aa3-441a-9058-65ba4c7ccaef
< 4.21.0
CRITICAL 9.8 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Privilege Escalat… — wordfence
a8082c60-436d-42e3-8aa5-cd2cb8ce6355 CRITICAL 9.8 includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes. — wordfence
a7b1871d-9d26-4bdc-bd20-0535143902d4
< 2.3
CRITICAL 9.8 The LWS Affiliation plugin for WordPress is vulnerable to Remote/Local File Inclusion in versions up to, and including, … — wordfence
a79bc789-ee03-4b7b-9835-5e20a4a70714 CRITICAL 9.8 The Simen theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6. This makes it… — wordfence
a76077c6-700a-4d21-a930-b0d6455d959c
< 3.0.5
CRITICAL 9.8 The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'w… — wordfence
a71a9aa0-ffe3-418d-ad18-285773ee01c1 CRITICAL 9.8 The Delete Comments By Status plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… — wordfence
a71a1a7b-6299-44c5-b686-65f214986c27
< 1.3.8
CRITICAL 9.8 The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.7… — wordfence
a6f362c1-fe64-4be1-9713-14c0561a59ce
< 3.3.2
CRITICAL 9.8 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due… — wordfence
a6d59ed7-a25e-4b96-a8de-9364aafdf72a CRITICAL 9.8 The Do That Task plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all… — wordfence
a6d474cb-36ca-4a99-82de-2e154b3ae6ac
< 2.0.22
CRITICAL 9.8 The Grow by Tradedoubler – Advertiser Plugin for WooCommerce plugin for WordPress is vulnerable to Local File Inclusio… — wordfence
a6bf60cc-4a07-4d5d-bff3-20d0115a5bd3
< 1.8.20
CRITICAL 9.8 The Gravityforms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via th… — wordfence
a6aeafd3-15be-49a3-be60-e33e909f32ca CRITICAL 9.8 The The Pressengine plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.… — wordfence
a69236d1-2164-4702-96e3-abd80fb5ffbb
< 1.2.0
CRITICAL 9.8 The Api2Cart Bridge Connector plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includi… — wordfence
a672c18b-1426-49fd-9590-eab8204afd5f
< 7.11.18
CRITICAL 9.8 In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize… — wordfence
a636e865-9556-4afb-8726-4537a160f379
< 1.8.7
CRITICAL 9.8 The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin… — wordfence
a6213e09-8a97-44cf-85ef-83179d79206c
< 4.0.5
CRITICAL 9.8 The LeagueManager plugin for WordPress is vulnerable to SQL Injection via the ‘match_id’ and 'league_id' parameters … — wordfence
a61cce43-0df7-4ca9-8897-24c7d131b505
< 1.0.3
CRITICAL 9.8 The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and … — wordfence
a61b2ecc-d4e1-4e71-9187-ddc3d3616a29
< 3.6.2.1
CRITICAL 9.8 The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all ver… — wordfence
a6196b07-a2fc-45ac-8700-a1ce2713a960
< 1.3.2
CRITICAL 9.8 WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attack… — wordfence
a60a9c14-d14e-469a-9cc5-681ca25db37c CRITICAL 9.8 The Easy CSV Importer BETA plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… — wordfence
a5f24902-1336-4fcd-b42d-e29526e61b71 CRITICAL 9.8 The Answer My Question plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in the 'modal.… — wordfence
a5e45e96-3cfb-42a9-b8b7-519489bc03ad
< 4.29.5
CRITICAL 9.8 Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for Wor… — wordfence
a5c290a1-b58a-4b5c-8112-076d5b17d940
< 1.2.5
CRITICAL 9.8 Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remot… — wordfence
← Prev 39 40 41 42 43 44 45 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top