πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 54 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7f99fc40-c5b8-4ce8-9422-9c02b1eca9cc
< 2.6.1
CRITICAL 9.8 The Foton theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5.2. This makes … wordfence
7f7ffa58-d942-4d60-9df4-6e646fadc23a CRITICAL 9.8 The Ahime Image Printer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.0… wordfence
7f7968c4-589c-4949-9f69-4a0ba4db4ea9
< 7.2
CRITICAL 9.8 The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i… wordfence
7f380786-7fd8-4a01-b491-63a2c6098a9e
< 2.0.0
CRITICAL 9.8 The CBX Petition for WordPress plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions … wordfence
7f2b424c-8f2b-4535-a556-0bd833eff2aa
< 1.5.10
CRITICAL 9.8 The Formality plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.9. This m… wordfence
7f26cf69-5dad-41ab-b302-6d4a753a9586 CRITICAL 9.8 The WeDesignTech Ultimate Booking Addon plugin for WordPress is vulnerable to Authentication Bypass in all versions up t… wordfence
7f1e81de-44fc-4125-b722-2c16c1f22ffa CRITICAL 9.8 The Portfolio Manager Pro - WordPress Responsive Portfolio & Gallery plugin for WordPress is vulnerable to arbitrary fil… wordfence
7f1a0d90-2574-4d48-b673-f47c8bc65d21
< 6.5.3
CRITICAL 9.8 The Easy Forms for Mailchimp plugin before 6.5.3 for WordPress has code injection via the admin input field. wordfence
7efacddc-3ca9-488b-a143-fe3a990d1324
< 2.6.8
CRITICAL 9.8 The WC Place Order Without Payment plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inc… wordfence
7ef64118-b388-4260-930b-6a31992d4076 CRITICAL 9.8 The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection. wordfence
7ebe84ba-abc1-410c-b315-118746ff235a
< 1.8.3
CRITICAL 9.8 The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privi… wordfence
7eb018bc-2650-4e0d-8da9-325eac826d45 CRITICAL 9.8 The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi… wordfence
7e9fec92-f471-4ce9-9138-1c58ad658da2
< 5.1.3
CRITICAL 9.8 The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restri… wordfence
7e9d3c2a-54af-4583-b008-b77ffad4e9cd CRITICAL 9.8 The Testimonial Slider And Showcase Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an… wordfence
7e987c38-b3a0-470e-9688-c8d79c853501 CRITICAL 9.8 The Woocommerce Product Design plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pa… wordfence
7e96c65d-be0f-4333-90d2-e1cc792f54b2 CRITICAL 9.8 The Debug Tool plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.2. Th… wordfence
7e8f230e-3f96-4efd-806d-72725b960303
< 2.2.2
CRITICAL 9.8 The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via … wordfence
7e7acb4d-7f4c-4b3f-a0df-7de99249034e
< 15.6.9
CRITICAL 9.8 The Simple Business Directory Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and … wordfence
7e402e3e-7b11-4931-8a4b-a80d26b9eb04
< 3.3.9
CRITICAL 9.8 The WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress plugin… wordfence
7de26eac-9726-4285-8f65-439f318d8687 CRITICAL 9.8 The advanced-custom-post-type plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc… wordfence
7dd7542a-357e-4a0f-879d-794b3451668e CRITICAL 9.8 The WhatsApp Click to Chat Plugin for WordPress plugin for WordPress is vulnerable to Local File Inclusion in versions u… wordfence
7dcc3c09-8bd2-4a08-a368-3f406170081e
< 3.0
CRITICAL 9.8 importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that au… wordfence
7dc9dc1c-2d79-4dc3-9fee-be5d591d2400
< 3.5.0
CRITICAL 9.8 The Google Analytics Counter Tracker plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and i… wordfence
7db04a93-a384-4093-8cab-6f1d6822f625
< 6.2
CRITICAL 9.8 The Formidable Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.1.2 … wordfence
7da4e3a2-29b3-47f3-b3fb-3a6ad0b8b8ac
< 5.3.0
CRITICAL 9.8 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Remote Code Execution in all ver… wordfence
← Prev 51 52 53 54 55 56 57 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top