πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 51 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8fcf7283-eb6c-4fee-b606-79026e2227fc
< 3.1.1
CRITICAL 9.8 The Profile Builder and Profile Builder Pro plugin versions up to and including 3.1.0 allows unauthenticated attackers t… — wordfence
8fc02501-2bb6-4817-8e01-273d3d91ac57
< 1.0.7
CRITICAL 9.8 SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote att… — wordfence
8fbc88da-8944-433c-b94d-9604ffe13d8a
< 0.4.2.2
CRITICAL 9.8 The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the up… — wordfence
8fbb92ac-a8e7-480d-8910-416fbe902a2a
< 5.1.3
CRITICAL 9.8 The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.… — wordfence
8fa4b5df-dc71-49de-880b-895eb1d9cdca
< 16.26.9
CRITICAL 9.8 The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/acco… — wordfence
8f8b1d8f-b2b6-415c-91f2-e5b98048258d
< 1.5.1
CRITICAL 9.8 The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0.… — wordfence
8f5fa529-4c6e-465e-a281-78ba74e5a718 CRITICAL 9.8 The Accordion plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/… — wordfence
8f3ed0f0-897d-47f4-acdc-b483838af4bc
< 2.3.5
CRITICAL 9.8 The SlideDeck 2 plugin for WordPress is vulnerable to Local/Remote File Inclusion in versions up to, and including, 2.3.… — wordfence
8f3c9b96-70e8-452e-9065-28dff744a69d
< 4.8.0
CRITICAL 9.8 The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.7.… — wordfence
8f20734d-4105-401b-992a-b47d049f70f4
< 2.0
CRITICAL 9.8 The AJAX Multi Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… — wordfence
8e7693a3-642a-4eff-902c-d29a3c12deb0
< 3.3.2
CRITICAL 9.8 The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authen… — wordfence
8e64d865-5acc-419b-8c61-e8fd8207fa94
< 3.1.4
CRITICAL 9.8 The Adifier System plugin for WordPress is vulnerable to SQL Injection in versions up to 3.1.4 due to insufficient escap… — wordfence
8e40a954-53c4-453b-85f0-d3febaa6ae84
< 4.3.6
CRITICAL 9.8 The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have auth… — wordfence
8e3e07c8-8fd0-4966-8276-aece794b75b2
< 3.1.1.4.2
CRITICAL 9.8 The Easy Digital Downloads plugin for WordPress is vulnerable to Unauthenticated Arbitrary Password Resets to Privilege … — wordfence
8e3c45ac-44c0-47e1-81af-65014f064513 CRITICAL 9.8 Several themes from Chimpstudio and Pixfill are vulnerable to arbitrary file uploads due to missing file type validation… — wordfence
8e2c6030-d117-4c0b-a97a-d0bb89e948ef CRITICAL 9.8 The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'upload… — wordfence
8dfa65cb-3d16-471a-8464-b71510d65fd5 CRITICAL 9.8 The Toolbox theme for WordPress is vulnerable to generic SQL Injection via the β€˜mls’ parameter in versions up to, an… — wordfence
8df66139-68bc-4bb4-80b5-aca604800ece
< 1.4.1
CRITICAL 9.8 The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulne… — wordfence
8de25651-4119-4806-91e4-4ea213086bfb
< 4.8.5
CRITICAL 9.8 The Hotel Booking Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… — wordfence
8ddf6964-e0e7-4093-8aea-ac33f4214122
< 2.6
CRITICAL 9.8 The Blaze Slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … — wordfence
8dd34937-7641-4b9c-ba59-c4a1ec95f4cd
< 3.8.0
CRITICAL 9.8 The Sweet Date theme for WordPress is vulnerable to privilege escalation due to a missing capability check on a function… — wordfence
8d3aea10-d7a0-44bd-94dc-3bad0d27dbd8 CRITICAL 9.8 The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inc… — wordfence
8d19e18d-6f2e-48e7-b8da-1d399dc4d65c
< 3.1.3
CRITICAL 9.8 Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to injec… — wordfence
8d132e9c-2dfb-49f6-bd35-9616f7932023
< 51.1.37
CRITICAL 9.8 The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin… — wordfence
8cf1276b-401d-4166-940e-e5d60f85e762
< 1.7.3
CRITICAL 9.8 The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to privilege … — wordfence
← Prev 48 49 50 51 52 53 54 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top