🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 46 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
979c1107-788a-4130-b1d1-5cad3717962b
< 1.2.7
CRITICAL 9.8 The OnionBuzz Plugin for WordPress is vulnerable to blind SQL Injection via the id parameter in versions up to, and incl… wordfence
979072fc-3bf9-4969-8e84-4648ec0928bd
< 1.5.0
CRITICAL 9.8 Multiple themes by bslthemes for WordPress are vulnerable to Local File Inclusion in various versions. This makes it pos… wordfence
978d1747-fbcf-4c08-9563-49041f225120 CRITICAL 9.8 The MoneyMasters theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the… wordfence
9781f10d-040d-4f2e-aac4-3aa395f364ec CRITICAL 9.8 The Image Classify plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… wordfence
9766a657-1cf2-448a-bd66-a27c0ebd8261
< 0.1.1
CRITICAL 9.8 The Payment Gateways Caller for WP e-Commerce plugin for WordPress is vulnerable to Local File Inclusion in versions bef… wordfence
9758a59c-4370-4b26-b32a-004565f28d76
< 3.2.0
CRITICAL 9.8 An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper in… wordfence
9754bdc9-5638-4227-87ee-3bda34d10e01
< 1.2
CRITICAL 9.8 The Easy Stripe – Tips, Payments, and Donations plugin for WordPress is vulnerable to Remote Code Execution in all ver… wordfence
96fc3ead-7ae4-4d2c-a0b5-13f3e3bf429b
< 2.3
CRITICAL 9.8 SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attack… wordfence
96f9c5b3-43b7-46e0-aa0c-a5179a99096b
< 3.6.8
CRITICAL 9.8 SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, … wordfence
969d35b5-2f2e-4255-b336-947414f269a5
< 2.38.5
CRITICAL 9.8 The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
9692deb2-2526-4983-8a13-93a382e230c8
< 5.1.9
CRITICAL 9.8 The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in al… wordfence
965dce53-2865-4179-9505-a64e4db1d1fd
< 1.0.83
CRITICAL 9.8 The OttoKit: All-in-One Automation Platform (Formerly SureTriggers) plugin for WordPress is vulnerable to Privilege Esca… wordfence
963f2485-3afa-4e17-8278-b75415af3915
< 0.1.0.45
CRITICAL 9.8 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in al… wordfence
95ff5150-ff45-48f8-bd39-0df79838942e
< 3.3.4
CRITICAL 9.8 The BetterDocs plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.3.3 vi… wordfence
95a68ae0-36da-499b-a09d-4c91db8aa338
< 3.0.9
CRITICAL 9.8 The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via th… wordfence
9555c48f-5ce3-4c0c-88f3-83776b42b808
< 13.1.6
CRITICAL 9.8 The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t… wordfence
9546ab46-737c-4bd3-9542-8ab1b776b3ea
< 2.14
CRITICAL 9.8 The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in al… wordfence
952e299a-5cec-444b-8359-3e7d8dec3ccb
< 6.03.01
CRITICAL 9.8 The Event Registration plugin for WordPress is vulnerable to generic SQL Injection via the ‘submitted_token’ and ‘… wordfence
9505b778-294f-45bc-a36c-22fbb894a294
< 3.1.0
CRITICAL 9.8 The LottieFiles plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
94fdc98a-c8be-47b4-a0a2-02d7373ab85e CRITICAL 9.8 The Talkback plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0 via deseri… wordfence
94d67030-30ea-4583-a716-79805a5619e8 CRITICAL 9.8 The Product Website Showcase plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and inc… wordfence
948d40f5-2c87-4439-b4ef-3e02c397bf0f
< 1.1.6
CRITICAL 9.8 The CP Appointment Calendar Plugin plugin for WordPress is vulnerable to SQL Injection via the $itemnumber variable in a… wordfence
94736152-b365-4b3a-a786-ed49f7d0fc7a
< 3.3.2
CRITICAL 9.8 The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3… wordfence
946d5a2c-f20f-483a-8150-0266a631a112
< 2.2
CRITICAL 9.8 The Homepage SlideShow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
94696151-9f99-4847-bd67-8fb77f8b6a0e CRITICAL 9.8 The BCorp Shortcodes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.… wordfence
← Prev 43 44 45 46 47 48 49 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top