πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 45 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9ae5b5f1-77a7-4626-a9b5-6f146c32a6db CRITICAL 9.8 The WordPress File Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
9aca80f2-61ab-4b7e-955e-d57f0cf5fb24
< 6.2.5
CRITICAL 9.8 The RSVPMaker for Toastmasters plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… wordfence
9aafc9a8-db81-4ba3-a0e3-1bf23df8bf31 CRITICAL 9.8 The Geolocator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1 via dese… wordfence
9a93313d-a5d7-4109-93c5-b2da26e7a486 CRITICAL 9.8 The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing… wordfence
9a6dce54-8d60-458c-90cd-e636413a388b CRITICAL 9.8 The Referrer Detector plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.1… wordfence
9a573740-cdfe-4b58-b33b-5e50bcbc4779
< 3.3.4
CRITICAL 9.8 The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3… wordfence
9a3c3b3b-7fc9-4586-9a51-33642654dc9f CRITICAL 9.8 SQL injection vulnerability in ss_handler.php in the WordPress Spreadsheet (wpSS) plugin 0.62 for WordPress allows remot… wordfence
9a1aa28f-0e8b-4961-abdd-c46b7fb3dceb
< 2.2
CRITICAL 9.8 The MediClinic theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1. This mak… wordfence
99ffffae-85a8-4562-838d-4e952bb0d76e CRITICAL 9.8 The Private Messages for UserPro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… wordfence
99d90610-490f-44a5-8e87-63927410c804 CRITICAL 9.8 A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re… wordfence
9970f9e5-ca20-4424-a501-9c8186ede497
< 2.2.1
CRITICAL 9.8 SQL injection vulnerability in BTE_RW_webajax.php in the Related Sites plugin 2.1 for WordPress allows remote attackers … wordfence
98ccc604-79c6-4be9-acb0-23fc82a31dfa
< 7.1.1
CRITICAL 9.8 The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the … wordfence
98ca009b-0e15-4945-a5c3-b08c081e7577
< 251005
CRITICAL 9.8 The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plug… wordfence
98c4192c-cf2c-46af-8c7b-02b59372f410 CRITICAL 9.8 The Molla - eCommerce HTML5 Template theme for WordPress is vulnerable to Remote Code Execution in all versions up to, a… wordfence
9890c852-a38d-4429-bd75-751bd0f986fc
< 4.2.0
CRITICAL 9.8 The LearnPress plugin for WordPress is vulnerable to SQL Injection in versions up to and including 4.1.7.3.2 due to insu… wordfence
987e228b-3a89-463e-aa4f-52d9edf911b2 CRITICAL 9.8 The SiteBuilder Dynamic Components plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inc… wordfence
98691973-0d7a-4fab-8d23-4105647cf728
< 1.6.3
CRITICAL 9.8 The Airin Blog theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.2 via des… wordfence
98541343-a23f-4e90-91c4-06cba4338281 CRITICAL 9.8 The Woocommerce Custom Profile Picture plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … wordfence
9834fd5b-8445-4c6f-95f9-f0df785c65f8 CRITICAL 9.8 The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that … wordfence
9831ebf6-a6a6-4495-8cda-969c7d7d3a6c
< 3.4.8
CRITICAL 9.8 The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing non… wordfence
982fb304-08d6-4195-97a3-f18e94295492
< 6.4.3
CRITICAL 9.8 The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-base… wordfence
9814c782-2a78-4501-be05-b759db99b485 CRITICAL 9.8 The Analyse Uploads plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validati… wordfence
980a9237-7dea-4058-a850-b849457b4fef
< 3.3.8
CRITICAL 9.8 The JupiterX Core plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 3.3.5 d… wordfence
98078b3f-cb7a-44fe-8619-088399bc3382
< 1.6.1
CRITICAL 9.8 The IvyPrep theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.0. This make… wordfence
979efaa4-10f1-4c7f-b4b0-5a41678c9d66
< 1.0.43
CRITICAL 9.8 The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42… wordfence
← Prev 42 43 44 45 46 47 48 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top