🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 47 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9be4ad83-14da-499e-b216-e5f26016fa35
< 3.6.8 RC1
CRITICAL 9.8 Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress al… — wordfence
9bd9c9db-d279-4de2-b5e4-ac7d8c919f2a CRITICAL 9.8 The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the… — wordfence
9bd3b7d6-7ad1-44f4-b28d-fdcb81692a8f
< 1.2.4
CRITICAL 9.8 The User Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3.… — wordfence
9bb430e6-0c30-4c23-874a-f91e25622857
< 1.110
CRITICAL 9.8 The MailCWP plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'mai… — wordfence
9bb2ae16-7886-4e66-83e0-59806dd67450
< 3.1.4
CRITICAL 9.8 A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfileP… — wordfence
9ba74e58-0647-4283-9fa3-428976c54474
< 3.7.40
CRITICAL 9.8 … — wordfence
9b5c2fb2-4274-460e-bb2b-567a0c3a7865 CRITICAL 9.8 The Navayan CSV Export plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.9 due t… — wordfence
9b5bdeb8-d5ee-4e30-8aaf-88893abf4145
< 2.0.2
CRITICAL 9.8 The Woocommerce Wordpress Auctions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type… — wordfence
9b458323-5fca-4fed-8c98-dfe69fd7a997 CRITICAL 9.8 The Downloads Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation o… — wordfence
9b3201e0-df2a-471e-875b-4ca2c3a659f3
< 3.0
CRITICAL 9.8 The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion. — wordfence
9ae9c422-8f5b-4ee4-ac3a-828c8230bf7b CRITICAL 9.8 The Docpro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.1. This make… — wordfence
9ae7b6fc-2120-4573-8b1b-d5422d435fa5
< 1.3.6.6
CRITICAL 9.8 The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in… — wordfence
9ae5b5f1-77a7-4626-a9b5-6f146c32a6db CRITICAL 9.8 The WordPress File Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… — wordfence
9aca80f2-61ab-4b7e-955e-d57f0cf5fb24
< 6.2.5
CRITICAL 9.8 The RSVPMaker for Toastmasters plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… — wordfence
9aafc9a8-db81-4ba3-a0e3-1bf23df8bf31 CRITICAL 9.8 The Geolocator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1 via dese… — wordfence
9a93313d-a5d7-4109-93c5-b2da26e7a486 CRITICAL 9.8 The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing… — wordfence
9a6dce54-8d60-458c-90cd-e636413a388b CRITICAL 9.8 The Referrer Detector plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.1… — wordfence
9a573740-cdfe-4b58-b33b-5e50bcbc4779
< 3.3.4
CRITICAL 9.8 The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3… — wordfence
9a3c3b3b-7fc9-4586-9a51-33642654dc9f CRITICAL 9.8 SQL injection vulnerability in ss_handler.php in the WordPress Spreadsheet (wpSS) plugin 0.62 for WordPress allows remot… — wordfence
9a3ba904-d0b7-4df1-a36a-3a36cc252641
< 1.0.3
CRITICAL 9.8 The DynamicKit for Elementor plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers… — wordfence
9a1aa28f-0e8b-4961-abdd-c46b7fb3dceb
< 2.2
CRITICAL 9.8 The MediClinic theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1. This mak… — wordfence
99ffffae-85a8-4562-838d-4e952bb0d76e CRITICAL 9.8 The Private Messages for UserPro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… — wordfence
99d90610-490f-44a5-8e87-63927410c804 CRITICAL 9.8 A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re… — wordfence
9970f9e5-ca20-4424-a501-9c8186ede497
< 2.2.1
CRITICAL 9.8 SQL injection vulnerability in BTE_RW_webajax.php in the Related Sites plugin 2.1 for WordPress allows remote attackers … — wordfence
98ccc604-79c6-4be9-acb0-23fc82a31dfa
< 7.1.1
CRITICAL 9.8 The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the … — wordfence
← Prev 44 45 46 47 48 49 50 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top