🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 48 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
916ada05-894e-4e61-ba0a-25b9a48461a1
< 1.2.0
CRITICAL 9.8 The LetsRecover plugin for WordPress is vulnerable to SQL Injection via an AJAX action in versions up to, and including,… wordfence
913ffe0c-c8f8-4cda-be9a-96c056d4c4a8
< 1.1
CRITICAL 9.8 The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.… wordfence
91286dc8-8015-4adc-9a21-d6187997cef4
< 3.6.1
CRITICAL 9.8 The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it … wordfence
911f3449-f906-493a-942b-eca26fdc10aa CRITICAL 9.8 The Avaz theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.8. This makes it … wordfence
911a9550-1f62-4f28-9d8c-00d9769949c9
< 1.2
CRITICAL 9.8 The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including… wordfence
9095bf69-e682-48aa-b206-8bd2b6c2b170
< 0.43.6
CRITICAL 9.8 The Sermon Browser plugin for WordPress is vulnerable to SQL Injection via the ‘sermon_id’ parameter in versions bef… wordfence
908dbe64-e214-4880-a85d-38df4c722a43 CRITICAL 9.8 The Dagda Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload… wordfence
90689ba2-4f82-4116-85d7-1266189aa34e
< 8.0.33
CRITICAL 9.8 The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api… wordfence
8ff54e1c-7d6c-4360-a9b3-4e8928fff6de CRITICAL 9.8 The Coming Soon, Maintenance Mode plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and incl… wordfence
8fd2ed33-6977-4480-bdcb-d7afae7bfd06 CRITICAL 9.8 SQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to e… wordfence
8fcf7283-eb6c-4fee-b606-79026e2227fc
< 3.1.1
CRITICAL 9.8 The Profile Builder and Profile Builder Pro plugin versions up to and including 3.1.0 allows unauthenticated attackers t… wordfence
8fc02501-2bb6-4817-8e01-273d3d91ac57
< 1.0.7
CRITICAL 9.8 SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote att… wordfence
8fbc88da-8944-433c-b94d-9604ffe13d8a
< 0.4.2.2
CRITICAL 9.8 The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the up… wordfence
8fa4b5df-dc71-49de-880b-895eb1d9cdca
< 16.26.9
CRITICAL 9.8 The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/acco… wordfence
8f8b1d8f-b2b6-415c-91f2-e5b98048258d
< 1.5.1
CRITICAL 9.8 The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0.… wordfence
8f5fa529-4c6e-465e-a281-78ba74e5a718 CRITICAL 9.8 The Accordion plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/… wordfence
8f3ed0f0-897d-47f4-acdc-b483838af4bc
< 2.3.5
CRITICAL 9.8 The SlideDeck 2 plugin for WordPress is vulnerable to Local/Remote File Inclusion in versions up to, and including, 2.3.… wordfence
8f3c9b96-70e8-452e-9065-28dff744a69d
< 4.8.0
CRITICAL 9.8 The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.7.… wordfence
8f20734d-4105-401b-992a-b47d049f70f4
< 2.0
CRITICAL 9.8 The AJAX Multi Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
8e7693a3-642a-4eff-902c-d29a3c12deb0
< 3.3.2
CRITICAL 9.8 The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authen… wordfence
8e64d865-5acc-419b-8c61-e8fd8207fa94
< 3.1.4
CRITICAL 9.8 The Adifier System plugin for WordPress is vulnerable to SQL Injection in versions up to 3.1.4 due to insufficient escap… wordfence
8e40a954-53c4-453b-85f0-d3febaa6ae84
< 4.3.6
CRITICAL 9.8 The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have auth… wordfence
8e3e07c8-8fd0-4966-8276-aece794b75b2
< 3.1.1.4.2
CRITICAL 9.8 The Easy Digital Downloads plugin for WordPress is vulnerable to Unauthenticated Arbitrary Password Resets to Privilege … wordfence
8e3c45ac-44c0-47e1-81af-65014f064513 CRITICAL 9.8 Several themes from Chimpstudio and Pixfill are vulnerable to arbitrary file uploads due to missing file type validation… wordfence
8e2c6030-d117-4c0b-a97a-d0bb89e948ef CRITICAL 9.8 The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'upload… wordfence
← Prev 45 46 47 48 49 50 51 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top