🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 47 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
944cd237-d5cb-44da-8d4a-5cf7edd368a4
< 1.2
CRITICAL 9.8 SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 fo… wordfence
942fd805-0f4f-44e5-98df-0b44ed8c7543
< 3.1
CRITICAL 9.8 The CouponXxL Custom Post Types plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and in… wordfence
941233d8-f382-40a0-81b2-18a682ae07ca
< 3.9.5
CRITICAL 9.8 The Ad manager & AdSense Ads for WordPress is vulnerable to blind SQL Injection via the ‘track’ parameter in version… wordfence
93b5552e-bb24-4dfb-a779-8451f619ff50
< 3.9.9.2
CRITICAL 9.8 The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functional… wordfence
936564ab-3119-4627-b7eb-4ca45ea377e5
< 1.0.6
CRITICAL 9.8 The AI Magic – SEO Content Generator & Article Writer plugin for WordPress is vulnerable to Privilege Escalation in al… wordfence
935caa43-4c75-47ad-a631-63988e21f834
< 2.2.1
CRITICAL 9.8 The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,… wordfence
934c3ce9-cf2d-4bf6-9a34-f448cb2e5a1d
< 2.1.6
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This… wordfence
933dd704-5a31-42a9-9b87-bf14a9d4ffa9
< 1.1.7
CRITICAL 9.8 The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in a… wordfence
9319dfc7-2b23-4056-8310-41a07535379d CRITICAL 9.8 The ajax-extend plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0 vi… wordfence
9312c73d-8eb6-4ca0-a03b-566099dc6487
< 1.4.3
CRITICAL 9.8 The WP GDPR Compliance plugin for WordPress is vulnerability to arbitrary options updates and action calling in version… wordfence
92f3b923-884e-4f61-9bf8-62dfb267a27e
< 1.5.2
CRITICAL 9.8 The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all vers… wordfence
92d5be7a-ce96-4e26-afd1-a84b6f46b03f
< 1.2.1
CRITICAL 9.8 The TAX SERVICE Electronic HDM plugin for WordPress is vulnerable to SQL Injection via the 'importTaxService' AJAX endpo… wordfence
92c79e51-3b14-4d1c-893b-a683b55f3011
< 4.2
CRITICAL 9.8 The Support Plus Responsive Ticket System plugin before 4.2 for WordPress has SQL injection. wordfence
92a120ac-66ae-4678-a87a-e62da885d50b
< 3.9.6
CRITICAL 9.8 The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.… wordfence
92a00fb4-7b50-43fd-ac04-5d6e29336e9c
< 0.1.0.39
CRITICAL 9.8 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates du… wordfence
92915943-c6ff-46df-adbd-382eabe44021
< 4.9.3
CRITICAL 9.8 The Manage WP Worker plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 4.9.2,… wordfence
928877a6-eeeb-4ed5-900b-9b1560e1bf87
< 2.5.01
CRITICAL 9.8 The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2… wordfence
92544c04-c499-420e-98f4-58834e579725 CRITICAL 9.8 The Custom css-js-php plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, … wordfence
923c513b-596f-44db-a98f-a33e8baec12e
< 1.6
CRITICAL 9.8 The Multiple Shipping And Billing Address For Woocommerce plugin for WordPress is vulnerable to PHP Object Injection in … wordfence
92321a3e-947b-4013-9b36-8bd6ea361f20
< 1.1.4
CRITICAL 9.8 The BBS e-Franchise for WordPress is vulnerable to generic SQL Injection via the ‘uid’ parameter in versions up to, … wordfence
92298f2d-aced-4177-b6e8-36e153e9c930
< 3.5.3
CRITICAL 9.8 The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on c… wordfence
91de6cf4-e5df-4130-bb96-92b89717a678
< 1.3.2
CRITICAL 9.8 The WP Frontend Profile plugin for WordPress is vulnerable to privilege in all versions up to, and including, 1.3.1. Thi… wordfence
91aa86d9-8e42-4deb-b6ca-c3b388fefcb1 CRITICAL 9.8 The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… wordfence
91a1604c-c729-4c68-90a8-91862a351ecc CRITICAL 9.8 The WP User plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.0 due to insufficien… wordfence
91754c4d-a0d0-4d35-a70a-446d2bdf6c73 CRITICAL 9.8 The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th… wordfence
← Prev 44 45 46 47 48 49 50 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top