🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 45 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a1817c58-e807-4ef2-a382-28ca2fd5239e
< 1.2.3
CRITICAL 9.8 The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This … — wordfence
a1800241-802b-4c6a-a9d8-a7cf78450346
< 1.4.3
CRITICAL 9.8 The WTI Like Post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTT… — wordfence
a146ea86-52a8-4488-b904-965409ec02ad CRITICAL 9.8 The Type Hub plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ver… — wordfence
a13c364f-bf86-41a9-b56e-949af38c01c6
< 1.1.0
CRITICAL 9.8 The Registration Form for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, … — wordfence
a135a298-0c8f-40d1-ad38-b55f81db0481
< 1.5.4
CRITICAL 9.8 The Kata Plus plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.3 via des… — wordfence
a10ba041-ded4-41d4-93ba-7fa7389acd54
< 2.1.8
CRITICAL 9.8 The WordPress OpenID Connect Client plugin for WordPress is vulnerable to authentication bypass in versions up to, and i… — wordfence
a10a3f01-082d-4a94-89c6-b5b46891aa4d
< 4.3.3
CRITICAL 9.8 The Gift Cards (Gift Vouchers and Packages) plugin for WordPress is vulnerable to SQL Injection via the 'template' param… — wordfence
a0da53ab-c750-4ff4-b3d1-49b6603182ae CRITICAL 9.8 The Private Feed Key plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0… — wordfence
a0cb0970-7e21-44ff-bbca-4b3e18f4466e
< 2.5.30
CRITICAL 9.8 Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows re… — wordfence
a0c67346-534a-4b67-a904-fa148703707a
< 6.17.4.1
CRITICAL 9.8 The "The Events Calendar" plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi… — wordfence
a0b37050-b320-4c59-8d93-db611aa55283
< 1.16.45
CRITICAL 9.8 The Booking Activities plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, … — wordfence
a0998721-7b5e-4657-894c-52dfadde5d4a
< 1.1.33
CRITICAL 9.8 The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Privilege Escalati… — wordfence
a08fa649-3092-4c26-a009-2dd576b9b1ac
< 2.6.1
CRITICAL 9.8 The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activ… — wordfence
a0695f66-5932-4ca4-86d3-ef53f1a669b5 CRITICAL 9.8 The Oberliga Theme for WordPress is vulnerable to generic SQL Injection via the ‘team’ parameter in all versions due… — wordfence
a042b1be-d39f-4d28-8566-d9974becdd40 CRITICAL 9.8 The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download func… — wordfence
a0146f17-35bd-45cf-b9c6-c4fce688efc2
< 1.1.2
CRITICAL 9.8 The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable… — wordfence
a003e922-d6c6-4f99-9b94-a3232d311677
< 5.4.02
CRITICAL 9.8 The Hide My WP Ghost plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.4.01… — wordfence
a00222f4-6f41-4a88-a50a-1e25b11a2ffc
< 1.2.9
CRITICAL 9.8 The Nika theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.8. This makes i… — wordfence
9fdb6e4d-a94d-448c-aaea-0f38eeafd033
< 2.5.4
CRITICAL 9.8 The WooLentor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.3 via des… — wordfence
9fb4c58d-321d-453f-92b9-ae409541911b
< 9.3.9
CRITICAL 9.8 The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.3.8. This m… — wordfence
9fb09a77-aba1-422c-961b-dc2c7ce82320
< 1.7.5.7
CRITICAL 9.8 The Cooked Pro plugin for WordPress is vulnerable to PHP Object Injection in versions up to, but not including, 1.7.5.7 … — wordfence
9fa30fa2-6c42-4e5f-a0b5-8711ce5d8121
< 2.150
CRITICAL 9.8 The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin … — wordfence
9f9fd9e1-c4b8-420e-a4d3-30c934853a98
< 12.6.7
CRITICAL 9.8 An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the A… — wordfence
9f606fba-f779-42ea-a160-6c3b20dc5e79
< 3.16.5
CRITICAL 9.8 The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up t… — wordfence
9f5cdb47-205a-4c03-a8a9-f39d1b4fc769
< 1.0.24
CRITICAL 9.8 The Agency Toolkit plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es… — wordfence
← Prev 42 43 44 45 46 47 48 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top