πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 48 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
98ca009b-0e15-4945-a5c3-b08c081e7577
< 251005
CRITICAL 9.8 The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plug… — wordfence
98c4192c-cf2c-46af-8c7b-02b59372f410 CRITICAL 9.8 The Molla - eCommerce HTML5 Template theme for WordPress is vulnerable to Remote Code Execution in all versions up to, a… — wordfence
9890c852-a38d-4429-bd75-751bd0f986fc
< 4.2.0
CRITICAL 9.8 The LearnPress plugin for WordPress is vulnerable to SQL Injection in versions up to and including 4.1.7.3.2 due to insu… — wordfence
987e228b-3a89-463e-aa4f-52d9edf911b2 CRITICAL 9.8 The SiteBuilder Dynamic Components plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inc… — wordfence
98691973-0d7a-4fab-8d23-4105647cf728
< 1.6.3
CRITICAL 9.8 The Airin Blog theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.2 via des… — wordfence
98541343-a23f-4e90-91c4-06cba4338281 CRITICAL 9.8 The Woocommerce Custom Profile Picture plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … — wordfence
9834fd5b-8445-4c6f-95f9-f0df785c65f8 CRITICAL 9.8 The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that … — wordfence
9831ebf6-a6a6-4495-8cda-969c7d7d3a6c
< 3.4.8
CRITICAL 9.8 The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing non… — wordfence
982fb304-08d6-4195-97a3-f18e94295492
< 6.4.3
CRITICAL 9.8 The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-base… — wordfence
9814c782-2a78-4501-be05-b759db99b485 CRITICAL 9.8 The Analyse Uploads plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validati… — wordfence
980a9237-7dea-4058-a850-b849457b4fef
< 3.3.8
CRITICAL 9.8 The JupiterX Core plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 3.3.5 d… — wordfence
98078b3f-cb7a-44fe-8619-088399bc3382
< 1.6.1
CRITICAL 9.8 The IvyPrep theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.0. This make… — wordfence
979efaa4-10f1-4c7f-b4b0-5a41678c9d66
< 1.0.43
CRITICAL 9.8 The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42… — wordfence
979c1107-788a-4130-b1d1-5cad3717962b
< 1.2.7
CRITICAL 9.8 The OnionBuzz Plugin for WordPress is vulnerable to blind SQL Injection via the id parameter in versions up to, and incl… — wordfence
979072fc-3bf9-4969-8e84-4648ec0928bd
< 1.5.0
CRITICAL 9.8 Multiple themes by bslthemes for WordPress are vulnerable to Local File Inclusion in various versions. This makes it pos… — wordfence
978d1747-fbcf-4c08-9563-49041f225120 CRITICAL 9.8 The MoneyMasters theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the… — wordfence
9781f10d-040d-4f2e-aac4-3aa395f364ec CRITICAL 9.8 The Image Classify plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… — wordfence
9766a657-1cf2-448a-bd66-a27c0ebd8261
< 0.1.1
CRITICAL 9.8 The Payment Gateways Caller for WP e-Commerce plugin for WordPress is vulnerable to Local File Inclusion in versions bef… — wordfence
9758a59c-4370-4b26-b32a-004565f28d76
< 3.2.0
CRITICAL 9.8 An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper in… — wordfence
9754bdc9-5638-4227-87ee-3bda34d10e01
< 1.2
CRITICAL 9.8 The Easy Stripe – Tips, Payments, and Donations plugin for WordPress is vulnerable to Remote Code Execution in all ver… — wordfence
96fc3ead-7ae4-4d2c-a0b5-13f3e3bf429b
< 2.3
CRITICAL 9.8 SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attack… — wordfence
96f9c5b3-43b7-46e0-aa0c-a5179a99096b
< 3.6.8
CRITICAL 9.8 SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, … — wordfence
96a2a552-e73f-4b27-88de-50eb63a8d131
< 4.4.2
CRITICAL 9.8 The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress… — wordfence
969d35b5-2f2e-4255-b336-947414f269a5
< 2.38.5
CRITICAL 9.8 The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … — wordfence
9692deb2-2526-4983-8a13-93a382e230c8
< 5.1.9
CRITICAL 9.8 The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in al… — wordfence
← Prev 45 46 47 48 49 50 51 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top