πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 43 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a5b7538f-891a-423f-97d1-b0212efcdb98
< 4.2.153
CRITICAL 9.8 An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almos… — wordfence
a597d36c-72ce-44f0-af7b-2b9aad46957c CRITICAL 9.8 The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does no… — wordfence
a57b2afa-b943-419f-9819-d7b6835c4d10 CRITICAL 9.8 The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p… — wordfence
a5763e3b-01b3-4541-8fef-80fcb7e7e88e
< 2.6.7
CRITICAL 9.8 The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authen… — wordfence
a5706025-962f-47e2-8d1d-16bafd937c92 CRITICAL 9.8 The Amoveo Multipurpose Wordpress Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type v… — wordfence
a56d5a2f-ae13-4523-bc4a-17bb2fb4c6f0
< 3.1
CRITICAL 9.8 The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /i… — wordfence
a56b59ce-29c2-4172-b703-a06d7bb28da0
< 7.8.0
CRITICAL 9.8 The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to auth… — wordfence
a537f82c-5139-439e-817f-7fd0ece958bd CRITICAL 9.8 The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to arbitrary file uploads due to inclusion… — wordfence
a5341bbd-55bd-41ad-b5d1-d6b56c141277
< 8.6.1
CRITICAL 9.8 The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and includi… — wordfence
a52e6242-33b4-4981-932f-d825b4fc9941 CRITICAL 9.8 The Prime Listing Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all version… — wordfence
a521b6a4-1a4f-4433-9163-8de71e1976dd
< 2.6.63
CRITICAL 9.8 The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to Privilege Escalation in all versi… — wordfence
a50b3304-d55b-487a-8137-d5083c704cf4
< 3.5.2
CRITICAL 9.8 The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi… — wordfence
a5082982-e605-4ab3-a5b8-785c1850da98
< 1.1.1
CRITICAL 9.8 The WPGuppy plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1.0 via deser… — wordfence
a4f8df3a-f247-4365-a9f6-6124065b4883
< 1.3.1
CRITICAL 9.8 The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in… — wordfence
a4e1315b-31e5-428c-9a48-6185b4eeb2fc
< 1.7.3
CRITICAL 9.8 The Bitcoin / AltCoin Payment Gateway for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up… — wordfence
a4d4532c-f29f-44e2-9aab-beab915efd3c CRITICAL 9.8 The FAT Cooming Soon plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. T… — wordfence
a4cbc0e7-4328-451f-a595-1ce17e9d0031
< 1.2.15
CRITICAL 9.8 The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1… — wordfence
a4b71893-b0fd-476e-aa93-5f0b239e8301
< 1.2
CRITICAL 9.8 The ColdFusion Responsive Fullscreen Video Image Audio Theme for WordPress is vulnerable to arbitrary file uploads due t… — wordfence
a4a26f60-5912-4d4a-8ef8-e4357c1fb1ff
< 3.9.4
CRITICAL 9.8 The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3… — wordfence
a4562535-ef69-4337-b03e-0b7c869cb042
< 3.1.11
CRITICAL 9.8 The Kadence Blocks for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the proc… — wordfence
a4294f5f-d989-4b97-88ee-4e94f4f7845a
< 3.0.8
CRITICAL 9.8 The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versi… — wordfence
a3fc4bac-9be0-4a1c-b4bb-4384d80e22f7
< 1.9.99
CRITICAL 9.8 The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file up… — wordfence
a3f173b6-f039-4865-8882-8ef7d1f88413
< 2.0
CRITICAL 9.8 The Cryptocurrency Widgets Pack plugin for WordPress is vulnerable to SQL Injection via one of its AJAX actions in versi… — wordfence
a3ee01da-218a-421d-8f9c-1dc6c056ef74
< 2.2.2.1
CRITICAL 9.8 The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inc… — wordfence
a3deedc4-b939-4c54-8376-95d3728872d4
< 2.2.83
CRITICAL 9.8 The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for … — wordfence
← Prev 40 41 42 43 44 45 46 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top