🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 43 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a0998721-7b5e-4657-894c-52dfadde5d4a
< 1.1.33
CRITICAL 9.8 The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Privilege Escalati… wordfence
a08fa649-3092-4c26-a009-2dd576b9b1ac
< 2.6.1
CRITICAL 9.8 The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activ… wordfence
a0695f66-5932-4ca4-86d3-ef53f1a669b5 CRITICAL 9.8 The Oberliga Theme for WordPress is vulnerable to generic SQL Injection via the ‘team’ parameter in all versions due… wordfence
a042b1be-d39f-4d28-8566-d9974becdd40 CRITICAL 9.8 The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download func… wordfence
a0146f17-35bd-45cf-b9c6-c4fce688efc2
< 1.1.2
CRITICAL 9.8 The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable… wordfence
a003e922-d6c6-4f99-9b94-a3232d311677
< 5.4.02
CRITICAL 9.8 The Hide My WP Ghost plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.4.01… wordfence
a00222f4-6f41-4a88-a50a-1e25b11a2ffc
< 1.2.9
CRITICAL 9.8 The Nika theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.8. This makes i… wordfence
9fdb6e4d-a94d-448c-aaea-0f38eeafd033
< 2.5.4
CRITICAL 9.8 The WooLentor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.3 via des… wordfence
9fb4c58d-321d-453f-92b9-ae409541911b
< 9.3.9
CRITICAL 9.8 The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.3.8. This m… wordfence
9fb09a77-aba1-422c-961b-dc2c7ce82320
< 1.7.5.7
CRITICAL 9.8 The Cooked Pro plugin for WordPress is vulnerable to PHP Object Injection in versions up to, but not including, 1.7.5.7 … wordfence
9fa30fa2-6c42-4e5f-a0b5-8711ce5d8121
< 2.150
CRITICAL 9.8 The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin … wordfence
9f9fd9e1-c4b8-420e-a4d3-30c934853a98
< 12.6.7
CRITICAL 9.8 An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the A… wordfence
9f5cdb47-205a-4c03-a8a9-f39d1b4fc769
< 1.0.24
CRITICAL 9.8 The Agency Toolkit plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es… wordfence
9f4fe2b2-c7a6-4e88-ac2e-2201072c4dac CRITICAL 9.8 The Advanced Online Ordering and Delivery Platform plugin for WordPress is vulnerable to Local File Inclusion in version… wordfence
9f301908-d491-492f-9347-432c462de286
< 7.3.15.727
CRITICAL 9.8 The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection. wordfence
9f130158-8c68-4a39-a94b-1f0ce81b1799 CRITICAL 9.8 The Custom Field List Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… wordfence
9ef3e6c7-b75a-4afc-b1c7-6e74b0c894a9
< 5.0.3
CRITICAL 9.8 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions… wordfence
9eb835fd-6ebf-4162-856c-0366b663a07e
< 4.2.3
CRITICAL 9.8 The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2… wordfence
9eb34cb2-ebf8-4913-b8e0-152a436963ee
< 3.2.2
CRITICAL 9.8 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to arbitrary file uploads due to mis… wordfence
9e7a1116-2bf1-4d36-a091-e0d4a9d6e1c9
< 1.3.8
CRITICAL 9.8 The InfiniteWP Client plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.3.7… wordfence
9e4d84ad-ab02-45b1-aecb-dc2c08c097fe
< 3.7.6
CRITICAL 9.8 The Dokan plugin for WordPress is vulnerable to SQL Injection via the ‘user_ids’ parameter in versions up to, and in… wordfence
9dfee325-9001-4483-b3eb-846da0314529
< 2.2.0
CRITICAL 9.8 The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via many parameters in versions up to, and including, … wordfence
9dfa4679-79d6-4444-9372-0753509ae93f
< 3.7
CRITICAL 9.8 The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.6. This… wordfence
9dda0b0a-234c-46bb-950a-2b7a5ef3227b CRITICAL 9.8 The Grace Mag theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.5. This ma… wordfence
9db30856-7541-4647-9e10-3855230b7efe
< 1.3.9
CRITICAL 9.8 The Zota theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.8. This makes i… wordfence
← Prev 40 41 42 43 44 45 46 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top