πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 42 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a3084a40-2b0b-402a-abd8-86bff47c9a0c CRITICAL 9.8 The Medical Prescription Attachment Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads … wordfence
a2fc40ed-a6af-4069-be63-cb75e98cc98a CRITICAL 9.8 The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.… wordfence
a2f8c71d-ad19-4265-8d33-3b0e7dbbf4c2 CRITICAL 9.8 The Monsters Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
a2e2cde5-f5e0-420c-8c0e-27206884eff9
< 3.4.3
CRITICAL 9.8 The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Remote Code Execution … wordfence
a2d6e595-0682-4a41-a432-afbcb50144e8 CRITICAL 9.8 The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,… wordfence
a2d22c5d-5ef5-4920-a1b5-e8284394c7e8
< 3.19.5
CRITICAL 9.8 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling o… wordfence
a2871261-3231-4a52-9a38-bb3caf461e7d
< 2.4
CRITICAL 9.8 The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inclu… wordfence
a260c173-9d3f-4b2d-b443-86488bd26292
< 2.6.8
CRITICAL 9.8 The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_dat… wordfence
a25528b1-28e0-4ac7-a7ab-2568b8349990 CRITICAL 9.8 The Famous theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the /mega… wordfence
a24af0ad-3204-4442-9e3e-8e57ab72e607
< 2.0.2
CRITICAL 9.8 The Capturly plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.1. This ma… wordfence
a234c996-3716-47b8-abab-8be9cb870997
< 1.0.4
CRITICAL 9.8 The Smart Agreements plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.3.… wordfence
a22932d8-14d4-43a1-86ba-7afadc0bec1a
< 1.4.3.2
CRITICAL 9.8 The Woopra Analytics Plugin for WordPress is vulnerable to Remote Code Execution in versions before 1.4.3.2 via the 'fil… wordfence
a213e844-a0d3-4123-9f72-caef7702804c
< 1.12.0
CRITICAL 9.8 The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPr… wordfence
a1f62cda-262b-46d9-a839-0a573813cfa1
< 6.0
CRITICAL 9.8 The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, … wordfence
a1e2d370-a716-4d6b-8e23-74db2fbd0760
< 1.3.14
CRITICAL 9.8 The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to,… wordfence
a1ce59bf-2d59-4c15-8be1-0d733526d1eb CRITICAL 9.8 The Shipyaari Shipping Management plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and incl… wordfence
a1bb2b06-9a3b-4428-8624-26a1202fe3b0
< 51.1.35
CRITICAL 9.8 The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is … wordfence
a1817c58-e807-4ef2-a382-28ca2fd5239e
< 1.2.3
CRITICAL 9.8 The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This … wordfence
a1800241-802b-4c6a-a9d8-a7cf78450346
< 1.4.3
CRITICAL 9.8 The WTI Like Post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTT… wordfence
a13c364f-bf86-41a9-b56e-949af38c01c6
< 1.1.0
CRITICAL 9.8 The Registration Form for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, … wordfence
a135a298-0c8f-40d1-ad38-b55f81db0481
< 1.5.4
CRITICAL 9.8 The Kata Plus plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.3 via des… wordfence
a10ba041-ded4-41d4-93ba-7fa7389acd54
< 2.1.8
CRITICAL 9.8 The WordPress OpenID Connect Client plugin for WordPress is vulnerable to authentication bypass in versions up to, and i… wordfence
a10a3f01-082d-4a94-89c6-b5b46891aa4d
< 4.3.3
CRITICAL 9.8 The Gift Cards (Gift Vouchers and Packages) plugin for WordPress is vulnerable to SQL Injection via the 'template' param… wordfence
a0cb0970-7e21-44ff-bbca-4b3e18f4466e
< 2.5.30
CRITICAL 9.8 Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows re… wordfence
a0b37050-b320-4c59-8d93-db611aa55283
< 1.16.45
CRITICAL 9.8 The Booking Activities plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, … wordfence
← Prev 39 40 41 42 43 44 45 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top