πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 52 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
855ca8f0-5078-48ec-a5d0-3f43a217a91e
< 2.1.0.10
CRITICAL 9.8 In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sani… wordfence
854e5d70-f42f-48c4-b1bb-687610f86cfb
< 2.06.04
CRITICAL 9.8 The "FireStorm Professional Real Estate Plugin" plugin for WordPress is vulnerable to SQL Injection via the 'id' paramet… wordfence
854ab1f3-5f7c-40a4-85a5-db4e20dc72cc
< 2.1
CRITICAL 9.8 The Manager for Icomoon plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
851daaab-4509-4a1e-b0bb-f9eda2b801c6 CRITICAL 9.8 The Malmonation theme for WordPress is vulnerable to SQL Injection via the β€˜id’ parameter in all versions due to ins… wordfence
850fc4db-6e02-44c7-836a-02c433a0bae7
< 4.8
CRITICAL 9.8 The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation … wordfence
84f08111-d116-46f9-9765-28966e338753 CRITICAL 9.8 The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includ… wordfence
84b75f7d-7258-46f6-aee6-b96d70bee264
< 1.3.9.1
CRITICAL 9.8 The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. Thi… wordfence
8494a17a-d6e7-4acb-b08f-3bc4aea0a488 CRITICAL 9.8 The LaunchPage.app Importer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1 du… wordfence
848f3b21-fb44-45c4-944e-7c4c62448ffc
< 8.1.1
CRITICAL 9.8 The L4 Shopping Cart Plugin for WordPress is vulnerable to SQL Injection via the β€˜id’ parameter in versions up to, a… wordfence
846fb218-ba71-41a2-af2f-931c2bfd5fdb
< 2.1.1
CRITICAL 9.8 The ForumWP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.0 via deser… wordfence
845fbf0f-c7c4-483e-b671-1a703d857792 CRITICAL 9.8 The WPB Show Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2 v… wordfence
843822f0-dd4c-4ae6-823d-96dd7a59df8e
< 1.5.2
CRITICAL 9.8 The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL inj… wordfence
84019c69-32fd-4331-95d7-53ea1aaff616
< 2.0.9.2
CRITICAL 9.8 The MainWP Child – Securely connects sites to the MainWP WordPress Manager Dashboard plugin for WordPress is vulnerabl… wordfence
83b062c8-4884-4ffa-89e6-71140c99e422
< 2.4
CRITICAL 9.8 The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) plugin for WordPress is vulnerable to SQL Injection in v… wordfence
8395e0c4-3feb-4551-9f2f-7b80cd187eca
< 1.4
CRITICAL 9.8 The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… wordfence
83009e29-6860-4d0c-954a-8035dc361cdc CRITICAL 9.8 The WP-lightpop plugin for WordPress is vulnerable to Remote Media File Inclusion in versions up to, and including, 0.8.… wordfence
82ffa37a-786c-4af7-8038-f452828160c9 CRITICAL 9.8 The WPKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privile… wordfence
82c3c97d-f9dd-4667-a1a8-94cf12947618
< 2.1
CRITICAL 9.8 The Goto - Tour & Travel WordPress Theme WordPress theme before 2.1 did not sanitise, validate of escape the keywords GE… wordfence
82b46474-9a32-4d7e-8fa4-91f6465c5fa7
< 1.1.0
CRITICAL 9.8 Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attack… wordfence
827b5482-cb42-4aaa-80b5-3d0143fcead8
< 5.1
CRITICAL 9.8 The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi… wordfence
8276ecfe-962b-4813-8011-4c8ca59d5389
< 1.5.3
CRITICAL 9.8 The Instant Image Generator (One Click Image Uploads from Pixabay, Pexels and OpenAI) plugin for WordPress is vulnerable… wordfence
8247acc4-04dc-463a-906a-f6085116cf40
< 2.2.4
CRITICAL 9.8 The Zingiri Web Shop plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.2.3… wordfence
82420667-9ba6-46ed-9a53-d16850755bb9
< 2.7.4
CRITICAL 9.8 The TI WooCommerce Wishlistplugin for WordPress is vulnerable to blind SQL Injection via the user_id parameter in versio… wordfence
81fb9d43-3c27-4de9-aa2e-66b783c78fa2
< 1.2.6
CRITICAL 9.8 The Enzio - Responsive Business WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions up… wordfence
81e7ab80-7df2-4ef4-80ee-a11d057151c4
< 1.2.0
CRITICAL 9.8 The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbi… wordfence
← Prev 49 50 51 52 53 54 55 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top