🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 51 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
885ee376-26cb-4330-9494-019b8870a982 CRITICAL 9.8 The La Boom theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7. This makes … wordfence
885eb923-8e69-416b-8494-a42a9465cfe0 CRITICAL 9.8 The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… wordfence
884dd491-c5b9-4278-9532-4896b6076f0a CRITICAL 9.8 The Multi Purpose Mail Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
8840bb3c-3e4b-48d5-bf01-2ed9bcfcf27a
< 1.5.11
CRITICAL 9.8 The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows… wordfence
87ec5542-b6e7-4b18-a3ec-c258e749d32e
< 5.2.1.1
CRITICAL 9.8 The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.… wordfence
87d153df-93b0-40a3-b119-9fad41fbd0ee
< 2.0.4
CRITICAL 9.8 Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable paramete… wordfence
87c7fe1a-c7d3-4d95-b3ed-da08c7428ad1 CRITICAL 9.8 The WDES Responsive Mobile Menu plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… wordfence
878420ce-3a39-494d-9169-44220b2c3307
< 1.4.3
CRITICAL 9.8 The iThemes2 Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the the… wordfence
876efd71-8867-44b8-8017-86fad2a1b89f
< 1.2.2
CRITICAL 9.8 The WP Fastest Cache plugin for WordPress is vulnerable to SQL Injection via the '$username' variable retrieved via user… wordfence
87399a07-d2d8-42cd-81f0-9060f6cfff48
< 1.2.0
CRITICAL 9.8 The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 … wordfence
86f91589-b309-49aa-8b04-ca972acaf8fb
< 7.8.5
CRITICAL 9.8 The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file upload… wordfence
86eb42de-a820-4ba7-99cb-03d068e208a9
< 0.9.2
CRITICAL 9.8 The Category and Page Icons plugin for WordPress is vulnerable to Arbitrary File Upload and Deletion due to a directory … wordfence
86d32797-a924-4d38-8543-eddb5f725d46 CRITICAL 9.8 The NIX Anti-Spam Light plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.0… wordfence
86becbbf-6d3c-4f06-bcb9-92167aad4084
< 1.2
CRITICAL 9.8 The Széchenyi 2020 Logo plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… wordfence
866f780e-46fa-407a-b777-951a328003dd CRITICAL 9.8 The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manua… wordfence
86609dfe-2060-4db2-8c5c-4e541302fc50
< 1.24.1
CRITICAL 9.8 The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to authorization bypass due to missing capabil… wordfence
8621bc52-3a71-4e01-9823-129ce0831ec4
< 2.5.96
CRITICAL 9.8 Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPres… wordfence
860e70be-2ccd-4d4d-b0d9-bde8d163c211 CRITICAL 9.8 The 123ContactForm for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v… wordfence
860b13d9-f906-4a10-98be-d4a7ac75d09d CRITICAL 9.8 The Acnoo Flutter API plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, … wordfence
8607acb6-743b-4a32-9941-27ce72379f0a CRITICAL 9.8 The Firebase OTP Authentication plugin for WordPress is vulnerable to privilege escalation via account takeover in all v… wordfence
85dc6513-90cb-433d-8f8f-5b56b4a76897
< 1.6.6
CRITICAL 9.8 Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress al… wordfence
85bea3da-f54a-4a77-9abe-6c24bbdcc25c
< 2.5.0
CRITICAL 9.8 The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files. wordfence
8599cb81-4f51-40b5-a0aa-5d27f2ae085d
< 2.9.8.6
CRITICAL 9.8 The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
8571b80b-a76d-4ade-98c9-c0bd44eee344
< 7.3.0.6
CRITICAL 9.8 The Uncanny Automator Pro plugin for WordPress contains a backdoor in all versions up to, and including, 7.3.0.5. This i… wordfence
855d3e2a-8ab1-4e7b-b435-f3c31171deeb
< 8.9.3
CRITICAL 9.8 WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation. wordfence
← Prev 48 49 50 51 52 53 54 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top