πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 44 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a3b2f3e0-4a91-42d4-b8a6-e0500fe30761 CRITICAL 9.8 The LinkedIn Lite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0. This… — wordfence
a353133d-0b36-40cc-a4f8-d5083e6e67df
< 1.2.7
CRITICAL 9.8 The GREYD.SUITE plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … — wordfence
a330f907-37d5-484c-94c5-b8d191796cd5
< 1.2
CRITICAL 9.8 Remote file upload vulnerability in fast-image-adder v1.1 Wordpress plugin — wordfence
a31af69d-f783-4d43-a14c-e153be3ee57c CRITICAL 9.8 The Selling Commander for WooCommerce – connector plugin plugin for WordPress is vulnerable to Privilege Escalation in… — wordfence
a3160602-6522-478d-8a99-d097472d10ac CRITICAL 9.8 The Sandbox theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the uplo… — wordfence
a30863c5-2e94-4952-b360-856394262023
< 4.2.22
CRITICAL 9.8 The Ultimate Product Catalog plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… — wordfence
a3084a40-2b0b-402a-abd8-86bff47c9a0c CRITICAL 9.8 The Medical Prescription Attachment Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads … — wordfence
a2fc40ed-a6af-4069-be63-cb75e98cc98a CRITICAL 9.8 The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.… — wordfence
a2f8c71d-ad19-4265-8d33-3b0e7dbbf4c2 CRITICAL 9.8 The Monsters Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … — wordfence
a2e2cde5-f5e0-420c-8c0e-27206884eff9
< 3.4.3
CRITICAL 9.8 The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Remote Code Execution … — wordfence
a2d6e595-0682-4a41-a432-afbcb50144e8 CRITICAL 9.8 The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,… — wordfence
a2d22c5d-5ef5-4920-a1b5-e8284394c7e8
< 3.19.5
CRITICAL 9.8 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling o… — wordfence
a2871261-3231-4a52-9a38-bb3caf461e7d
< 2.4
CRITICAL 9.8 The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inclu… — wordfence
a260c173-9d3f-4b2d-b443-86488bd26292
< 2.6.8
CRITICAL 9.8 The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_dat… — wordfence
a25528b1-28e0-4ac7-a7ab-2568b8349990 CRITICAL 9.8 The Famous theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the /mega… — wordfence
a24af0ad-3204-4442-9e3e-8e57ab72e607
< 2.0.2
CRITICAL 9.8 The Capturly plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.1. This ma… — wordfence
a234c996-3716-47b8-abab-8be9cb870997
< 1.0.4
CRITICAL 9.8 The Smart Agreements plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.3.… — wordfence
a22932d8-14d4-43a1-86ba-7afadc0bec1a
< 1.4.3.2
CRITICAL 9.8 The Woopra Analytics Plugin for WordPress is vulnerable to Remote Code Execution in versions before 1.4.3.2 via the 'fil… — wordfence
a213e844-a0d3-4123-9f72-caef7702804c
< 1.12.0
CRITICAL 9.8 The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPr… — wordfence
a1f62cda-262b-46d9-a839-0a573813cfa1
< 6.0
CRITICAL 9.8 The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, … — wordfence
a1e2d370-a716-4d6b-8e23-74db2fbd0760
< 1.3.14
CRITICAL 9.8 The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to,… — wordfence
a1ce59bf-2d59-4c15-8be1-0d733526d1eb CRITICAL 9.8 The Shipyaari Shipping Management plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and incl… — wordfence
a1bb2b06-9a3b-4428-8624-26a1202fe3b0
< 51.1.35
CRITICAL 9.8 The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is … — wordfence
a19c70d1-30d6-4d87-92a7-46841951e1c7
< 2.7.1
CRITICAL 9.8 The Migratico Lite plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.6… — wordfence
a192d097-79f8-42ce-8941-5a7b9f2b2df6 CRITICAL 9.8 The WP Social Media Login plugin for WordPress is vulnerable to Authentication Bypass via the Twitter login flow in all… — wordfence
← Prev 41 42 43 44 45 46 47 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top