πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 44 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9d979d09-a019-420e-b46e-b1d1f5e430ae
< 5.5.0
CRITICAL 9.8 The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Privilege Escalation … wordfence
9d8551b8-67b9-45a8-9357-9e42fb451606 CRITICAL 9.8 The Ya'aburnee and Dignitas themes for WordPress are vulnerable to Privilege Escalation in versions up to, and including… wordfence
9d4bbf48-6525-4569-98a6-412f2bfe7628 CRITICAL 9.8 The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php. wordfence
9cd87da6-1f4c-4a15-8ebb-6e0f8ef72513
< 1.25.0
CRITICAL 9.8 The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after … wordfence
9c7d2321-735a-4b5f-a36d-16375c994d2d
< 2.9.8
CRITICAL 9.8 The Paid Memberships Pro plugin for WordPress is vulnerable to SQL injection in versions before 2.9.8 via the 'code' par… wordfence
9c78e0b6-bf24-4a23-8501-b26e681a7a4a
< 2.0.0
CRITICAL 9.8 The Author Char plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 1.9.0 due … wordfence
9c3df12d-e526-4a23-89d3-bfdcea9f7b2d
< 3.6.1
CRITICAL 9.8 The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in ve… wordfence
9c35ca72-6ce9-40de-a413-12455bfb610e CRITICAL 9.8 The Meta Keywords & Description plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… wordfence
9c269233-f2dc-42ef-98be-78600f90e87d CRITICAL 9.8 The MainWP Links Manager Extension plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inc… wordfence
9c14d918-daf9-46e8-9f96-4215e4645c62 CRITICAL 9.8 The GNUCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.4 via d… wordfence
9c101fca-037c-4bed-9dc7-baa021a8b59c
< 1.8.5
CRITICAL 9.8 The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing ca… wordfence
9bfcc607-9fbc-4d36-858d-a0f763597a3b CRITICAL 9.8 The ZoomSounds plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.91 via des… wordfence
9be94d63-f027-4988-ab41-673658c1fa5f
< 18.0
CRITICAL 9.8 The WooCommerce Checkout Field Manager plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient … wordfence
9be4ad83-14da-499e-b216-e5f26016fa35
< 3.6.8 RC1
CRITICAL 9.8 Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress al… wordfence
9bd9c9db-d279-4de2-b5e4-ac7d8c919f2a CRITICAL 9.8 The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the… wordfence
9bd3b7d6-7ad1-44f4-b28d-fdcb81692a8f
< 1.2.4
CRITICAL 9.8 The User Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3.… wordfence
9bb430e6-0c30-4c23-874a-f91e25622857
< 1.110
CRITICAL 9.8 The MailCWP plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'mai… wordfence
9bb2ae16-7886-4e66-83e0-59806dd67450
< 3.1.4
CRITICAL 9.8 A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfileP… wordfence
9ba74e58-0647-4283-9fa3-428976c54474
< 3.7.40
CRITICAL 9.8 wordfence
9b5c2fb2-4274-460e-bb2b-567a0c3a7865 CRITICAL 9.8 The Navayan CSV Export plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.9 due t… wordfence
9b5bdeb8-d5ee-4e30-8aaf-88893abf4145
< 2.0.2
CRITICAL 9.8 The Woocommerce Wordpress Auctions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type… wordfence
9b458323-5fca-4fed-8c98-dfe69fd7a997 CRITICAL 9.8 The Downloads Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation o… wordfence
9b3201e0-df2a-471e-875b-4ca2c3a659f3
< 3.0
CRITICAL 9.8 The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion. wordfence
9ae9c422-8f5b-4ee4-ac3a-828c8230bf7b CRITICAL 9.8 The Docpro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.1. This make… wordfence
9ae7b6fc-2120-4573-8b1b-d5422d435fa5
< 1.3.6.6
CRITICAL 9.8 The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in… wordfence
← Prev 41 42 43 44 45 46 47 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top