πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 5 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
be3a0b4b-cce5-4d78-99d5-697f2cf04427
< 1.9.16
CRITICAL 9.9 The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
b54f38b6-5f98-469c-802a-a4c1e1f2ab0e
< 2.0.8
CRITICAL 9.9 Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or cu… wordfence
afb5b791-0bc7-466f-87f6-f6c5ebed576b CRITICAL 9.9 The Import Export For WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … wordfence
adb1d8b0-b1d6-40df-b591-f1062ee744fb
< 18.3
CRITICAL 9.9 The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and inc… wordfence
a979e885-f7dd-4616-a881-64f3d97c309d
< 3.0.2.1
CRITICAL 9.9 The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and… wordfence
a169934d-17ce-4d34-be00-c5ac0b488066
< 4.9.50
CRITICAL 9.9 The WooCommerce Follow-Up Emails plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v… wordfence
a14cf955-e354-49c3-a685-d5bd51c79ba9
< 29.7
CRITICAL 9.9 The WooCommerce Customers Manager plugin for WordPress is vulnerable to SQL Injection via the 'max_amount_total' paramet… wordfence
a14c04e8-72cc-4415-a95c-e26f6335b485
< 14.11
CRITICAL 9.9 SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remo… wordfence
9a09102c-391e-4057-b883-3d2eef1671ce
< 1.5.61
CRITICAL 9.9 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file upl… wordfence
97ed0ef5-2a01-4531-a844-81766bdfc7c8
< 16.26.6
CRITICAL 9.9 The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection in all vers… wordfence
9670bd32-34ce-48b1-82d9-62ab8869a89b
< 2.4.12
CRITICAL 9.9 The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attri… wordfence
964d6dd2-0e93-4fc2-87ca-0257186d1b37
< 3.9.0
CRITICAL 9.9 The Shipment Tracking, Tracking, and Order Tracking for WooCommerce – ParcelPanel (Free to install) plugin for WordPre… wordfence
9476b41d-a9a2-46a7-8cf1-62de5d1703b1
< 5.7.9
CRITICAL 9.9 The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.8 due to insu… wordfence
93f377a1-2c33-4dd7-8fd6-190d9148e804
< 7.2.2
CRITICAL 9.9 The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and… wordfence
8f50812a-c6a7-4bb3-9833-e10acd0460c0
< 1.3.3.4
CRITICAL 9.9 The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attr… wordfence
8edb060b-349c-46bb-9440-94f753621111 CRITICAL 9.9 The Gallery – Image and Video Gallery with Thumbnails plugin for WordPress is vulnerable to SQL Injection in all versi… wordfence
8d54079a-1a7e-4391-b7ee-d06d7f8b2312
< 3.9.2
CRITICAL 9.9 The Greenshift Query and Meta Addon plugin for WordPress is vulnerable to SQL Injection in versions up to 3.9.2 due to i… wordfence
8d03af4d-a1f9-4c15-a62e-f4cdbcfc9af7
< 4.0.8
CRITICAL 9.9 The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code … wordfence
8c57211a-f59d-4379-b09e-7c6049a6b04d
< 1.5.6
CRITICAL 9.9 The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including,… wordfence
8c2707ae-8dc0-417c-be4b-83db7dda9c76
< 3.5
CRITICAL 9.9 The WP Poll Maker – Best WordPress Poll Plugin for Voting Contest plugin for WordPress is vulnerable to arbitrary file… wordfence
8c0dc694-854e-4f96-8c2d-7251c41a3ee9
< 1.6.2
CRITICAL 9.9 The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability che… wordfence
8b104666-a038-442f-8db8-78ccb64879a7
< 2.9.5
CRITICAL 9.9 The ListingPro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.4 due to insuff… wordfence
866e4bc3-080a-4498-b210-e692d72d3db0
< 2024.09.14
CRITICAL 9.9 The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_ver… wordfence
8647005a-23ce-417f-9bdb-c54ac506942b
< 1.1.18
CRITICAL 9.9 The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to SQL Injection in ver… wordfence
84090828-f132-4848-8d84-dfff79b44818
< 3.27
CRITICAL 9.9 The CSV to html plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … wordfence
← Prev 2 3 4 5 6 7 8 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top