🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 50 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8b783b94-7135-49c1-aff2-1c2ea24bbfcd
< 1.11
CRITICAL 9.8 The CIP4 Folder Download Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… wordfence
8b4fcc97-1b6b-4411-8b55-0ef7a2c8d44e
< 9.6.2
CRITICAL 9.8 Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effe… wordfence
8b4e2f87-e3ad-4f1b-b647-f5e5a49f691b
< 2.3.9
CRITICAL 9.8 The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due t… wordfence
8b29bc45-dff5-49e2-9a18-8c4a89edd424
< 1.7.1
CRITICAL 9.8 The CozyStay theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.7.1 via deserialization of un… wordfence
8afe386e-1e4f-4668-8309-6d47dedb008a CRITICAL 9.8 The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an… wordfence
8ada8a27-752c-4726-b330-895b967ea290
< 3.9.0
CRITICAL 9.8 The WordPress File Upload plugin is vulnerable to arbitrary file uploads due to insufficient file type validation in ver… wordfence
8a96d6d5-a5e3-4648-902b-f9d1f8e57e5c CRITICAL 9.8 The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… wordfence
8a8ae1b0-e9a0-4179-970b-dbcb0642547c
< 3.20.0
CRITICAL 9.8 The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.… wordfence
8a876469-72b1-478f-926b-57da237e3a95
< 2.2.1
CRITICAL 9.8 The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion. wordfence
8a52bf70-667b-400f-8912-75fae20a3f5b
< 7.1.9.8
CRITICAL 9.8 The Checkout Mestres WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
8a4ae629-51c8-4acc-bf95-fb0282e88383
< 1.5.4
CRITICAL 9.8 SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote… wordfence
8a2df1f5-3843-4745-b251-ad40a9272b7b CRITICAL 9.8 The Xpresslane Fast Checkout plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… wordfence
8a2186c9-fa27-4d7d-be41-c82711c49334
< 2.3.11
CRITICAL 9.8 The WP User Frontend plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
8a1d90f6-40fc-40b5-a46c-9ba9ac2fc1b5
< 2.13.3
CRITICAL 9.8 The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. T… wordfence
8a00ece0-6644-4535-86aa-d0802d94a1a7
< 1.3.0
CRITICAL 9.8 The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing … wordfence
89a9d925-6ca3-481f-ba7d-ea9869d51b52
< 2.24
CRITICAL 9.8 The GiveWP plugin for WordPress is vulnerable to SQL Injection versions up to, and including, 2.23.2 due to insufficien… wordfence
89904362-4ac2-450a-89ac-8935fdb4976d
< 1.8.8.1
CRITICAL 9.8 Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows … wordfence
89620065-b961-49c9-a662-bee300b5da72 CRITICAL 9.8 The Lightspeed theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via VALUM… wordfence
89586fcc-f0f6-4f44-841b-04eee64c0ab3
< 3.8.3.3
CRITICAL 9.8 The Pie Register plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… wordfence
89584034-4a93-42a6-8fef-55dc3895c45c
< 2.11.1
CRITICAL 9.8 The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.… wordfence
8950b98d-7e7d-4cad-bb3d-d7a5d8edbdf5
< 5.6
CRITICAL 9.8 The ARMember Premium plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including, 5.5.1.… wordfence
8911642f-6061-42a1-b733-8cc44b2870f1
< 1.3.76
CRITICAL 9.8 The Ultimate Member plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in vers… wordfence
88f4c567-eb57-4f98-afdc-65f8863b90c3
< 2.1
CRITICAL 9.8 The WordPress Job Board and Recruitment Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missi… wordfence
88eb424b-112e-4580-b883-baba360c1ecd CRITICAL 9.8 The Verbalize WP plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all… wordfence
888877c9-45e1-405a-ac0c-bbe512188141 CRITICAL 9.8 The Youtube Freedown plugin for WordPress is vulnerable to Remote Media File Inclusion in versions up to, and including,… wordfence
← Prev 47 48 49 50 51 52 53 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top