🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 46 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9f4fe2b2-c7a6-4e88-ac2e-2201072c4dac CRITICAL 9.8 The Advanced Online Ordering and Delivery Platform plugin for WordPress is vulnerable to Local File Inclusion in version… — wordfence
9f301908-d491-492f-9347-432c462de286
< 7.3.15.727
CRITICAL 9.8 The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection. — wordfence
9f130158-8c68-4a39-a94b-1f0ce81b1799 CRITICAL 9.8 The Custom Field List Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… — wordfence
9ef3e6c7-b75a-4afc-b1c7-6e74b0c894a9
< 5.0.3
CRITICAL 9.8 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions… — wordfence
9eb835fd-6ebf-4162-856c-0366b663a07e
< 4.2.3
CRITICAL 9.8 The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2… — wordfence
9eb34cb2-ebf8-4913-b8e0-152a436963ee
< 3.2.2
CRITICAL 9.8 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to arbitrary file uploads due to mis… — wordfence
9e7a1116-2bf1-4d36-a091-e0d4a9d6e1c9
< 1.3.8
CRITICAL 9.8 The InfiniteWP Client plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.3.7… — wordfence
9e4d84ad-ab02-45b1-aecb-dc2c08c097fe
< 3.7.6
CRITICAL 9.8 The Dokan plugin for WordPress is vulnerable to SQL Injection via the ‘user_ids’ parameter in versions up to, and in… — wordfence
9dfee325-9001-4483-b3eb-846da0314529
< 2.2.0
CRITICAL 9.8 The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via many parameters in versions up to, and including, … — wordfence
9dfa4679-79d6-4444-9372-0753509ae93f
< 3.7
CRITICAL 9.8 The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.6. This… — wordfence
9dda0b0a-234c-46bb-950a-2b7a5ef3227b CRITICAL 9.8 The Grace Mag theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.5. This ma… — wordfence
9db30856-7541-4647-9e10-3855230b7efe
< 1.3.9
CRITICAL 9.8 The Zota theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.8. This makes i… — wordfence
9d979d09-a019-420e-b46e-b1d1f5e430ae
< 5.5.0
CRITICAL 9.8 The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Privilege Escalation … — wordfence
9d8551b8-67b9-45a8-9357-9e42fb451606 CRITICAL 9.8 The Ya'aburnee and Dignitas themes for WordPress are vulnerable to Privilege Escalation in versions up to, and including… — wordfence
9d4bbf48-6525-4569-98a6-412f2bfe7628 CRITICAL 9.8 The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php. — wordfence
9cd87da6-1f4c-4a15-8ebb-6e0f8ef72513
< 1.25.0
CRITICAL 9.8 The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after … — wordfence
9c7d2321-735a-4b5f-a36d-16375c994d2d
< 2.9.8
CRITICAL 9.8 The Paid Memberships Pro plugin for WordPress is vulnerable to SQL injection in versions before 2.9.8 via the 'code' par… — wordfence
9c78e0b6-bf24-4a23-8501-b26e681a7a4a
< 2.0.0
CRITICAL 9.8 The Author Char plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 1.9.0 due … — wordfence
9c3df12d-e526-4a23-89d3-bfdcea9f7b2d
< 3.6.1
CRITICAL 9.8 The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in ve… — wordfence
9c35ca72-6ce9-40de-a413-12455bfb610e CRITICAL 9.8 The Meta Keywords & Description plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… — wordfence
9c269233-f2dc-42ef-98be-78600f90e87d CRITICAL 9.8 The MainWP Links Manager Extension plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inc… — wordfence
9c14d918-daf9-46e8-9f96-4215e4645c62 CRITICAL 9.8 The GNUCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.4 via d… — wordfence
9c101fca-037c-4bed-9dc7-baa021a8b59c
< 1.8.5
CRITICAL 9.8 The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing ca… — wordfence
9bfcc607-9fbc-4d36-858d-a0f763597a3b CRITICAL 9.8 The ZoomSounds plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.91 via des… — wordfence
9be94d63-f027-4988-ab41-673658c1fa5f
< 18.0
CRITICAL 9.8 The WooCommerce Checkout Field Manager plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient … — wordfence
← Prev 43 44 45 46 47 48 49 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top