🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 49 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
965dce53-2865-4179-9505-a64e4db1d1fd
< 1.0.83
CRITICAL 9.8 The OttoKit: All-in-One Automation Platform (Formerly SureTriggers) plugin for WordPress is vulnerable to Privilege Esca… — wordfence
963f2485-3afa-4e17-8278-b75415af3915
< 0.1.0.45
CRITICAL 9.8 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in al… — wordfence
95ff5150-ff45-48f8-bd39-0df79838942e
< 3.3.4
CRITICAL 9.8 The BetterDocs plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.3.3 vi… — wordfence
95a68ae0-36da-499b-a09d-4c91db8aa338
< 3.0.9
CRITICAL 9.8 The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via th… — wordfence
9555c48f-5ce3-4c0c-88f3-83776b42b808
< 13.1.6
CRITICAL 9.8 The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t… — wordfence
9546ab46-737c-4bd3-9542-8ab1b776b3ea
< 2.14
CRITICAL 9.8 The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in al… — wordfence
952e299a-5cec-444b-8359-3e7d8dec3ccb
< 6.03.01
CRITICAL 9.8 The Event Registration plugin for WordPress is vulnerable to generic SQL Injection via the ‘submitted_token’ and ‘… — wordfence
9505b778-294f-45bc-a36c-22fbb894a294
< 3.1.0
CRITICAL 9.8 The LottieFiles plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… — wordfence
94fdc98a-c8be-47b4-a0a2-02d7373ab85e CRITICAL 9.8 The Talkback plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0 via deseri… — wordfence
94e987be-bdfc-4691-b250-2b7d7249df0a
< 2.29.0
CRITICAL 9.8 The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.28.… — wordfence
94d67030-30ea-4583-a716-79805a5619e8 CRITICAL 9.8 The Product Website Showcase plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and inc… — wordfence
948d40f5-2c87-4439-b4ef-3e02c397bf0f
< 1.1.6
CRITICAL 9.8 The CP Appointment Calendar Plugin plugin for WordPress is vulnerable to SQL Injection via the $itemnumber variable in a… — wordfence
94736152-b365-4b3a-a786-ed49f7d0fc7a
< 3.3.2
CRITICAL 9.8 The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3… — wordfence
946d5a2c-f20f-483a-8150-0266a631a112
< 2.2
CRITICAL 9.8 The Homepage SlideShow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … — wordfence
94696151-9f99-4847-bd67-8fb77f8b6a0e CRITICAL 9.8 The BCorp Shortcodes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.… — wordfence
944cd237-d5cb-44da-8d4a-5cf7edd368a4
< 1.2
CRITICAL 9.8 SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 fo… — wordfence
942fd805-0f4f-44e5-98df-0b44ed8c7543
< 3.1
CRITICAL 9.8 The CouponXxL Custom Post Types plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and in… — wordfence
941233d8-f382-40a0-81b2-18a682ae07ca
< 3.9.5
CRITICAL 9.8 The Ad manager & AdSense Ads for WordPress is vulnerable to blind SQL Injection via the ‘track’ parameter in version… — wordfence
93b5552e-bb24-4dfb-a779-8451f619ff50
< 3.9.9.2
CRITICAL 9.8 The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functional… — wordfence
936564ab-3119-4627-b7eb-4ca45ea377e5
< 1.0.6
CRITICAL 9.8 The AI Magic – SEO Content Generator & Article Writer plugin for WordPress is vulnerable to Privilege Escalation in al… — wordfence
935caa43-4c75-47ad-a631-63988e21f834
< 2.2.1
CRITICAL 9.8 The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,… — wordfence
934c3ce9-cf2d-4bf6-9a34-f448cb2e5a1d
< 2.1.6
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This… — wordfence
933dd704-5a31-42a9-9b87-bf14a9d4ffa9
< 1.1.7
CRITICAL 9.8 The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in a… — wordfence
9319dfc7-2b23-4056-8310-41a07535379d CRITICAL 9.8 The ajax-extend plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0 vi… — wordfence
9312c73d-8eb6-4ca0-a03b-566099dc6487
< 1.4.3
CRITICAL 9.8 The WP GDPR Compliance plugin for WordPress is vulnerability to arbitrary options updates and action calling in version… — wordfence
← Prev 46 47 48 49 50 51 52 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top