🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 53 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8a876469-72b1-478f-926b-57da237e3a95
< 2.2.1
CRITICAL 9.8 The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion. — wordfence
8a52bf70-667b-400f-8912-75fae20a3f5b
< 7.1.9.8
CRITICAL 9.8 The Checkout Mestres WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… — wordfence
8a4ae629-51c8-4acc-bf95-fb0282e88383
< 1.5.4
CRITICAL 9.8 SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote… — wordfence
8a2df1f5-3843-4745-b251-ad40a9272b7b CRITICAL 9.8 The Xpresslane Fast Checkout plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… — wordfence
8a2186c9-fa27-4d7d-be41-c82711c49334
< 2.3.11
CRITICAL 9.8 The WP User Frontend plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… — wordfence
8a1d90f6-40fc-40b5-a46c-9ba9ac2fc1b5
< 2.13.3
CRITICAL 9.8 The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. T… — wordfence
8a00ece0-6644-4535-86aa-d0802d94a1a7
< 1.3.0
CRITICAL 9.8 The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing … — wordfence
89a9d925-6ca3-481f-ba7d-ea9869d51b52
< 2.24
CRITICAL 9.8 The GiveWP plugin for WordPress is vulnerable to SQL Injection versions up to, and including, 2.23.2 due to insufficien… — wordfence
89904362-4ac2-450a-89ac-8935fdb4976d
< 1.8.8.1
CRITICAL 9.8 Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows … — wordfence
89620065-b961-49c9-a662-bee300b5da72 CRITICAL 9.8 The Lightspeed theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via VALUM… — wordfence
89586fcc-f0f6-4f44-841b-04eee64c0ab3
< 3.8.3.3
CRITICAL 9.8 The Pie Register plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… — wordfence
89584034-4a93-42a6-8fef-55dc3895c45c
< 2.11.1
CRITICAL 9.8 The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.… — wordfence
8950b98d-7e7d-4cad-bb3d-d7a5d8edbdf5
< 5.6
CRITICAL 9.8 The ARMember Premium plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including, 5.5.1.… — wordfence
8911642f-6061-42a1-b733-8cc44b2870f1
< 1.3.76
CRITICAL 9.8 The Ultimate Member plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in vers… — wordfence
88f4c567-eb57-4f98-afdc-65f8863b90c3
< 2.1
CRITICAL 9.8 The WordPress Job Board and Recruitment Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missi… — wordfence
88eb424b-112e-4580-b883-baba360c1ecd CRITICAL 9.8 The Verbalize WP plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all… — wordfence
8898bae3-067c-4505-9a96-05b7a08d90c6 CRITICAL 9.8 The Admin Menu Editor Pro plugin for WordPress contains a backdoor in versions 2.35 to 2.36. This is due to their infras… — wordfence
888877c9-45e1-405a-ac0c-bbe512188141 CRITICAL 9.8 The Youtube Freedown plugin for WordPress is vulnerable to Remote Media File Inclusion in versions up to, and including,… — wordfence
885ee376-26cb-4330-9494-019b8870a982 CRITICAL 9.8 The La Boom theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7. This makes … — wordfence
885eb923-8e69-416b-8494-a42a9465cfe0 CRITICAL 9.8 The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… — wordfence
884dd491-c5b9-4278-9532-4896b6076f0a CRITICAL 9.8 The Multi Purpose Mail Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… — wordfence
8840bb3c-3e4b-48d5-bf01-2ed9bcfcf27a
< 1.5.11
CRITICAL 9.8 The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows… — wordfence
87ec5542-b6e7-4b18-a3ec-c258e749d32e
< 5.2.1.1
CRITICAL 9.8 The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.… — wordfence
87d6322c-3031-47c7-a1ad-2ce805e58755
< 2.3.3
CRITICAL 9.8 The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Arbitrary File Up… — wordfence
87d153df-93b0-40a3-b119-9fad41fbd0ee
< 2.0.4
CRITICAL 9.8 Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable paramete… — wordfence
← Prev 50 51 52 53 54 55 56 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top