🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 53 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
81c62f9d-6a98-4f18-8c4a-c81c2730ce5d CRITICAL 9.8 The Ads Booster by Ads Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … wordfence
81b44abb-6d30-4930-b68b-9a04d93f5169
< 2.1.0
CRITICAL 9.8 The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0… wordfence
819b9565-2eb1-4b87-bf3a-5cd93429cafe
< 3.7.1.5
CRITICAL 9.8 The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form &… wordfence
81505a97-7244-4318-87b8-a04042bb1eca CRITICAL 9.8 The Ajar in5 Embed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t… wordfence
8148b6d0-190a-4b97-8af7-edd6943116d1
< 2.1.3
CRITICAL 9.8 The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on th… wordfence
81354461-70a9-4a5d-9a75-1f2445f7e8aa CRITICAL 9.8 The wp-realty plugin for WordPress is vulnerable to time-based blind SQL Injection in versions up to, and including, 2.9… wordfence
812029d9-95d6-4bc9-98b2-700f462163b3
< 4.2.15
CRITICAL 9.8 The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Lim… wordfence
8114905a-f08c-425f-ae48-06302cfcb20a CRITICAL 9.8 The Switchblade - Powerful WordPress Theme for WordPress is vulnerable to arbitrary file uploads due to missing file typ… wordfence
80fcb3af-0b27-4442-aca0-58626b68f0d9
< 5.0.2
CRITICAL 9.8 The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0… wordfence
80e74852-517e-4cd0-a7d3-6f6fe3433bff
< 0.3.0
CRITICAL 9.8 The WPGraphQL versions up to 0.2.3 for WordPress allows remote attackers to register a new user with admin privileges, w… wordfence
80dbb49d-d21d-41ef-90af-f74f46e5b703 CRITICAL 9.8 SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin version… wordfence
80b099db-682e-48ad-8efb-d94abe6e4e61
< 1.1.29
CRITICAL 9.8 The Fana theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.28. This makes … wordfence
808392a9-dbac-4896-8677-6ddc1213d80d
< 1.8.6
CRITICAL 9.8 The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
8071f117-c341-45bc-8d6e-8aa5d677d65c
< 3.3.4
CRITICAL 9.8 The WordPress WP-Advanced-Search plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and incl… wordfence
806e5056-5c29-49d0-9150-add6ee485758
< 2.9.5.118
CRITICAL 9.8 The Simple Ads Manager plugin for WordPress is vulnerable to unspecified SQL Injection via the ‘whereClause’ paramet… wordfence
8064526f-edd3-43e4-9732-47b25ab256fe
< 2.0
CRITICAL 9.8 The Cryptocurrency Widgets Pack plugin for WordPress is vulnerable to generic SQL Injection via an unknown parameter in … wordfence
8057937d-69d2-4d33-828b-d8b50351189b
< 1.3.9
CRITICAL 9.8 The Diza theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.8. This makes i… wordfence
80440bfa-4a02-4441-bbdb-52d7dd065a9d
< 1.7.0
CRITICAL 9.8 The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptograp… wordfence
8028b14b-8a41-4284-9560-4b8595e7eaa9 CRITICAL 9.8 SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers… wordfence
80178b72-56ff-448f-a558-de0b63198e44
< 1.5.7
CRITICAL 9.8 The Simple Registration for WooCommerce plugin for WordPress is vulnerable to privilege escalation in all versions up to… wordfence
7ff230b0-c186-41fc-93a5-2ed90e8aab4d
< 4.0
CRITICAL 9.8 The ARMember plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and includi… wordfence
7fdd670f-2a71-4c1d-af46-f0fd05352f7e CRITICAL 9.8 The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… wordfence
7fcde31b-6a58-4d8a-887f-1b2221b72c77
< 1.4.6
CRITICAL 9.8 The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-ca… wordfence
7fc410f2-5f2b-4eea-a0fb-fe58f988f95f
< 1.8.61
CRITICAL 9.8 The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in version… wordfence
7fb646c4-6269-4354-b3a6-872c6303a6d2
< 2.2.0
CRITICAL 9.8 The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Sensitive Information Exp… wordfence
← Prev 50 51 52 53 54 55 56 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top