🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 54 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
87c7fe1a-c7d3-4d95-b3ed-da08c7428ad1 CRITICAL 9.8 The WDES Responsive Mobile Menu plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… — wordfence
878420ce-3a39-494d-9169-44220b2c3307
< 1.4.3
CRITICAL 9.8 The iThemes2 Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the the… — wordfence
876efd71-8867-44b8-8017-86fad2a1b89f
< 1.2.2
CRITICAL 9.8 The WP Fastest Cache plugin for WordPress is vulnerable to SQL Injection via the '$username' variable retrieved via user… — wordfence
87399a07-d2d8-42cd-81f0-9060f6cfff48
< 1.2.0
CRITICAL 9.8 The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 … — wordfence
872e1a05-aacc-44fa-93c1-8c3f7b2fb46d
< 3.5.51
CRITICAL 9.8 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file… — wordfence
86f91589-b309-49aa-8b04-ca972acaf8fb
< 7.8.5
CRITICAL 9.8 The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file upload… — wordfence
86eb42de-a820-4ba7-99cb-03d068e208a9
< 0.9.2
CRITICAL 9.8 The Category and Page Icons plugin for WordPress is vulnerable to Arbitrary File Upload and Deletion due to a directory … — wordfence
86d32797-a924-4d38-8543-eddb5f725d46 CRITICAL 9.8 The NIX Anti-Spam Light plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.0… — wordfence
86becbbf-6d3c-4f06-bcb9-92167aad4084
< 1.2
CRITICAL 9.8 The Széchenyi 2020 Logo plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… — wordfence
866f780e-46fa-407a-b777-951a328003dd CRITICAL 9.8 The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manua… — wordfence
86609dfe-2060-4db2-8c5c-4e541302fc50
< 1.24.1
CRITICAL 9.8 The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to authorization bypass due to missing capabil… — wordfence
8631462c-75cd-4452-8698-e0d5b8f0963f CRITICAL 9.8 The Teddy Bear Customize Addon plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and in… — wordfence
8621bc52-3a71-4e01-9823-129ce0831ec4
< 2.5.96
CRITICAL 9.8 Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPres… — wordfence
860e70be-2ccd-4d4d-b0d9-bde8d163c211 CRITICAL 9.8 The 123ContactForm for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v… — wordfence
860b13d9-f906-4a10-98be-d4a7ac75d09d CRITICAL 9.8 The Acnoo Flutter API plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, … — wordfence
8607acb6-743b-4a32-9941-27ce72379f0a CRITICAL 9.8 The Firebase OTP Authentication plugin for WordPress is vulnerable to privilege escalation via account takeover in all v… — wordfence
85dc6513-90cb-433d-8f8f-5b56b4a76897
< 1.6.6
CRITICAL 9.8 Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress al… — wordfence
85bea3da-f54a-4a77-9abe-6c24bbdcc25c
< 2.5.0
CRITICAL 9.8 The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files. — wordfence
8599cb81-4f51-40b5-a0aa-5d27f2ae085d
< 2.9.8.6
CRITICAL 9.8 The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … — wordfence
8571b80b-a76d-4ade-98c9-c0bd44eee344
< 7.3.0.6
CRITICAL 9.8 The Uncanny Automator Pro plugin for WordPress contains a backdoor in all versions up to, and including, 7.3.0.5. This i… — wordfence
855d3e2a-8ab1-4e7b-b435-f3c31171deeb
< 8.9.3
CRITICAL 9.8 WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation. — wordfence
855ca8f0-5078-48ec-a5d0-3f43a217a91e
< 2.1.0.10
CRITICAL 9.8 In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sani… — wordfence
854e5d70-f42f-48c4-b1bb-687610f86cfb
< 2.06.04
CRITICAL 9.8 The "FireStorm Professional Real Estate Plugin" plugin for WordPress is vulnerable to SQL Injection via the 'id' paramet… — wordfence
854ab1f3-5f7c-40a4-85a5-db4e20dc72cc
< 2.1
CRITICAL 9.8 The Manager for Icomoon plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… — wordfence
851daaab-4509-4a1e-b0bb-f9eda2b801c6 CRITICAL 9.8 The Malmonation theme for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions due to ins… — wordfence
← Prev 51 52 53 54 55 56 57 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top