πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 52 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8cd1d385-001c-4c84-9a80-553315336a63 CRITICAL 9.8 The WPJobBoard plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.0 due to insuff… — wordfence
8ccb1304-326e-43af-b75d-23874f92ba8b
< 2.0.45
CRITICAL 9.8 The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification p… — wordfence
8cbf5121-2511-4e21-a346-67fa1e34fc02 CRITICAL 9.8 The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.… — wordfence
8cb6c075-81f8-491d-bcef-6974861424db
< 1.8.71
CRITICAL 9.8 The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to OTP Brute Force in all versions … — wordfence
8ca830d6-3d3c-4026-85cd-8447b8a568d3
< 3.4.2
CRITICAL 9.8 The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vul… — wordfence
8ca7b2ab-bc01-4fd7-9cee-7cdc5a62177d CRITICAL 9.8 The Echelon theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/lib… — wordfence
8c852eb8-4b55-48e1-95e8-43e9a2962015 CRITICAL 9.8 The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Local Fi… — wordfence
8c652a98-2762-4ecf-8037-58377d6e1b5a
< 1.44
CRITICAL 9.8 The wordTube plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.43 via the 'w… — wordfence
8c5042aa-80d6-47c3-aa85-7e16f40aa47d CRITICAL 9.8 The WHMpress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.2-revision-9… — wordfence
8c3ef1bf-ef81-4e24-9813-de1a25b0e8ae
< 4.6.8.6
CRITICAL 9.8 The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. — wordfence
8c04d8c9-acad-4832-aa8a-8372c58a0387
< 3.0.9.5
CRITICAL 9.8 The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress … — wordfence
8bd81f3c-f801-4fc6-b2db-754e5ebed688
< 1.6.1.1
CRITICAL 9.8 The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.0… — wordfence
8bd035bf-003f-4f97-be76-7b1c50727d21
< 2.6.0
CRITICAL 9.8 The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Privilege Escalation… — wordfence
8bc0969f-7b29-41fb-8d41-869049f87c7d CRITICAL 9.8 The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [… — wordfence
8b865fde-1c47-4574-932c-334ebefb3579 CRITICAL 9.8 Directory traversal vulnerability in main.php in the WP-Lytebox plugin 1.3 for WordPress allows remote attackers to incl… — wordfence
8b818586-99a2-4865-bd5b-3c77e9aca29e
< 1.9
CRITICAL 9.8 The Dessau theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.9. This makes it possible for u… — wordfence
8b7c9d89-c6bf-4973-87c8-0511758519f7
< 1.5.35
CRITICAL 9.8 SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/control… — wordfence
8b783b94-7135-49c1-aff2-1c2ea24bbfcd
< 1.11
CRITICAL 9.8 The CIP4 Folder Download Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… — wordfence
8b4fcc97-1b6b-4411-8b55-0ef7a2c8d44e
< 9.6.2
CRITICAL 9.8 Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effe… — wordfence
8b4e2f87-e3ad-4f1b-b647-f5e5a49f691b
< 2.3.9
CRITICAL 9.8 The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due t… — wordfence
8b29bc45-dff5-49e2-9a18-8c4a89edd424
< 1.7.1
CRITICAL 9.8 The CozyStay theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.7.1 via deserialization of un… — wordfence
8afe386e-1e4f-4668-8309-6d47dedb008a CRITICAL 9.8 The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an… — wordfence
8ada8a27-752c-4726-b330-895b967ea290
< 3.9.0
CRITICAL 9.8 The WordPress File Upload plugin is vulnerable to arbitrary file uploads due to insufficient file type validation in ver… — wordfence
8a96d6d5-a5e3-4648-902b-f9d1f8e57e5c CRITICAL 9.8 The WPη§»θ‘Œε°‚η”¨γƒ—γƒ©γ‚°γ‚€γƒ³ for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… — wordfence
8a8ae1b0-e9a0-4179-970b-dbcb0642547c
< 3.20.0
CRITICAL 9.8 The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.… — wordfence
← Prev 49 50 51 52 53 54 55 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top