🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 50 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
92f3b923-884e-4f61-9bf8-62dfb267a27e
< 1.5.2
CRITICAL 9.8 The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all vers… — wordfence
92d5be7a-ce96-4e26-afd1-a84b6f46b03f
< 1.2.1
CRITICAL 9.8 The TAX SERVICE Electronic HDM plugin for WordPress is vulnerable to SQL Injection via the 'importTaxService' AJAX endpo… — wordfence
92c79e51-3b14-4d1c-893b-a683b55f3011
< 4.2
CRITICAL 9.8 The Support Plus Responsive Ticket System plugin before 4.2 for WordPress has SQL injection. — wordfence
92a120ac-66ae-4678-a87a-e62da885d50b
< 3.9.6
CRITICAL 9.8 The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.… — wordfence
92a00fb4-7b50-43fd-ac04-5d6e29336e9c
< 0.1.0.39
CRITICAL 9.8 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates du… — wordfence
92915943-c6ff-46df-adbd-382eabe44021
< 4.9.3
CRITICAL 9.8 The Manage WP Worker plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 4.9.2,… — wordfence
928877a6-eeeb-4ed5-900b-9b1560e1bf87
< 2.5.01
CRITICAL 9.8 The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2… — wordfence
92544c04-c499-420e-98f4-58834e579725 CRITICAL 9.8 The Custom css-js-php plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, … — wordfence
923c513b-596f-44db-a98f-a33e8baec12e
< 1.6
CRITICAL 9.8 The Multiple Shipping And Billing Address For Woocommerce plugin for WordPress is vulnerable to PHP Object Injection in … — wordfence
92321a3e-947b-4013-9b36-8bd6ea361f20
< 1.1.4
CRITICAL 9.8 The BBS e-Franchise for WordPress is vulnerable to generic SQL Injection via the ‘uid’ parameter in versions up to, … — wordfence
92298f2d-aced-4177-b6e8-36e153e9c930
< 3.5.3
CRITICAL 9.8 The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on c… — wordfence
91de6cf4-e5df-4130-bb96-92b89717a678
< 1.3.2
CRITICAL 9.8 The WP Frontend Profile plugin for WordPress is vulnerable to privilege in all versions up to, and including, 1.3.1. Thi… — wordfence
91aa86d9-8e42-4deb-b6ca-c3b388fefcb1 CRITICAL 9.8 The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… — wordfence
91a1604c-c729-4c68-90a8-91862a351ecc CRITICAL 9.8 The WP User plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.0 due to insufficien… — wordfence
91754c4d-a0d0-4d35-a70a-446d2bdf6c73 CRITICAL 9.8 The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th… — wordfence
916ada05-894e-4e61-ba0a-25b9a48461a1
< 1.2.0
CRITICAL 9.8 The LetsRecover plugin for WordPress is vulnerable to SQL Injection via an AJAX action in versions up to, and including,… — wordfence
913ffe0c-c8f8-4cda-be9a-96c056d4c4a8
< 1.1
CRITICAL 9.8 The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.… — wordfence
91286dc8-8015-4adc-9a21-d6187997cef4
< 3.6.1
CRITICAL 9.8 The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it … — wordfence
911f3449-f906-493a-942b-eca26fdc10aa CRITICAL 9.8 The Avaz theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.8. This makes it … — wordfence
911a9550-1f62-4f28-9d8c-00d9769949c9
< 1.2
CRITICAL 9.8 The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including… — wordfence
9095bf69-e682-48aa-b206-8bd2b6c2b170
< 0.43.6
CRITICAL 9.8 The Sermon Browser plugin for WordPress is vulnerable to SQL Injection via the ‘sermon_id’ parameter in versions bef… — wordfence
908dbe64-e214-4880-a85d-38df4c722a43 CRITICAL 9.8 The Dagda Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload… — wordfence
90689ba2-4f82-4116-85d7-1266189aa34e
< 8.0.33
CRITICAL 9.8 The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api… — wordfence
8ff54e1c-7d6c-4360-a9b3-4e8928fff6de CRITICAL 9.8 The Coming Soon, Maintenance Mode plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and incl… — wordfence
8fd2ed33-6977-4480-bdcb-d7afae7bfd06 CRITICAL 9.8 SQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to e… — wordfence
← Prev 47 48 49 50 51 52 53 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top