πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 49 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8dfa65cb-3d16-471a-8464-b71510d65fd5 CRITICAL 9.8 The Toolbox theme for WordPress is vulnerable to generic SQL Injection via the β€˜mls’ parameter in versions up to, an… wordfence
8df66139-68bc-4bb4-80b5-aca604800ece
< 1.4.1
CRITICAL 9.8 The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulne… wordfence
8de25651-4119-4806-91e4-4ea213086bfb
< 4.8.5
CRITICAL 9.8 The Hotel Booking Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… wordfence
8ddf6964-e0e7-4093-8aea-ac33f4214122
< 2.6
CRITICAL 9.8 The Blaze Slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
8dd34937-7641-4b9c-ba59-c4a1ec95f4cd
< 3.8.0
CRITICAL 9.8 The Sweet Date theme for WordPress is vulnerable to privilege escalation due to a missing capability check on a function… wordfence
8d3aea10-d7a0-44bd-94dc-3bad0d27dbd8 CRITICAL 9.8 The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inc… wordfence
8d19e18d-6f2e-48e7-b8da-1d399dc4d65c
< 3.1.3
CRITICAL 9.8 Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to injec… wordfence
8d132e9c-2dfb-49f6-bd35-9616f7932023
< 51.1.37
CRITICAL 9.8 The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin… wordfence
8cf1276b-401d-4166-940e-e5d60f85e762
< 1.7.3
CRITICAL 9.8 The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to privilege … wordfence
8cd1d385-001c-4c84-9a80-553315336a63 CRITICAL 9.8 The WPJobBoard plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.0 due to insuff… wordfence
8ccb1304-326e-43af-b75d-23874f92ba8b
< 2.0.45
CRITICAL 9.8 The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification p… wordfence
8cbf5121-2511-4e21-a346-67fa1e34fc02 CRITICAL 9.8 The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.… wordfence
8ca830d6-3d3c-4026-85cd-8447b8a568d3
< 3.4.2
CRITICAL 9.8 The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vul… wordfence
8ca7b2ab-bc01-4fd7-9cee-7cdc5a62177d CRITICAL 9.8 The Echelon theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/lib… wordfence
8c852eb8-4b55-48e1-95e8-43e9a2962015 CRITICAL 9.8 The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Local Fi… wordfence
8c652a98-2762-4ecf-8037-58377d6e1b5a
< 1.44
CRITICAL 9.8 The wordTube plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.43 via the 'w… wordfence
8c5042aa-80d6-47c3-aa85-7e16f40aa47d CRITICAL 9.8 The WHMpress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.2-revision-9… wordfence
8c3ef1bf-ef81-4e24-9813-de1a25b0e8ae
< 4.6.8.6
CRITICAL 9.8 The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. wordfence
8c04d8c9-acad-4832-aa8a-8372c58a0387
< 3.0.9.5
CRITICAL 9.8 The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress … wordfence
8bd81f3c-f801-4fc6-b2db-754e5ebed688
< 1.6.1.1
CRITICAL 9.8 The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.0… wordfence
8bd035bf-003f-4f97-be76-7b1c50727d21
< 2.6.0
CRITICAL 9.8 The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Privilege Escalation… wordfence
8bc0969f-7b29-41fb-8d41-869049f87c7d CRITICAL 9.8 The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [… wordfence
8b865fde-1c47-4574-932c-334ebefb3579 CRITICAL 9.8 Directory traversal vulnerability in main.php in the WP-Lytebox plugin 1.3 for WordPress allows remote attackers to incl… wordfence
8b818586-99a2-4865-bd5b-3c77e9aca29e
< 1.9
CRITICAL 9.8 The Dessau theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.9. This makes it possible for u… wordfence
8b7c9d89-c6bf-4973-87c8-0511758519f7
< 1.5.35
CRITICAL 9.8 SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/control… wordfence
← Prev 46 47 48 49 50 51 52 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top