πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 55 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
850fc4db-6e02-44c7-836a-02c433a0bae7
< 4.8
CRITICAL 9.8 The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation … — wordfence
84f08111-d116-46f9-9765-28966e338753 CRITICAL 9.8 The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includ… — wordfence
84b75f7d-7258-46f6-aee6-b96d70bee264
< 1.3.9.1
CRITICAL 9.8 The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. Thi… — wordfence
84afe5a7-1bf4-4b83-bf77-efbb003a30cd
< 3.34.2
CRITICAL 9.8 The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authent… — wordfence
8494a17a-d6e7-4acb-b08f-3bc4aea0a488 CRITICAL 9.8 The LaunchPage.app Importer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1 du… — wordfence
848f3b21-fb44-45c4-944e-7c4c62448ffc
< 8.1.1
CRITICAL 9.8 The L4 Shopping Cart Plugin for WordPress is vulnerable to SQL Injection via the β€˜id’ parameter in versions up to, a… — wordfence
846fb218-ba71-41a2-af2f-931c2bfd5fdb
< 2.1.1
CRITICAL 9.8 The ForumWP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.0 via deser… — wordfence
845fbf0f-c7c4-483e-b671-1a703d857792 CRITICAL 9.8 The WPB Show Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2 v… — wordfence
843822f0-dd4c-4ae6-823d-96dd7a59df8e
< 1.5.2
CRITICAL 9.8 The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL inj… — wordfence
84019c69-32fd-4331-95d7-53ea1aaff616
< 2.0.9.2
CRITICAL 9.8 The MainWP Child – Securely connects sites to the MainWP WordPress Manager Dashboard plugin for WordPress is vulnerabl… — wordfence
83b062c8-4884-4ffa-89e6-71140c99e422
< 2.4
CRITICAL 9.8 The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) plugin for WordPress is vulnerable to SQL Injection in v… — wordfence
8395e0c4-3feb-4551-9f2f-7b80cd187eca
< 1.4
CRITICAL 9.8 The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… — wordfence
83009e29-6860-4d0c-954a-8035dc361cdc CRITICAL 9.8 The WP-lightpop plugin for WordPress is vulnerable to Remote Media File Inclusion in versions up to, and including, 0.8.… — wordfence
82ffa37a-786c-4af7-8038-f452828160c9 CRITICAL 9.8 The WPKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privile… — wordfence
82c3c97d-f9dd-4667-a1a8-94cf12947618
< 2.1
CRITICAL 9.8 The Goto - Tour & Travel WordPress Theme WordPress theme before 2.1 did not sanitise, validate of escape the keywords GE… — wordfence
82b46474-9a32-4d7e-8fa4-91f6465c5fa7
< 1.1.0
CRITICAL 9.8 Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attack… — wordfence
827b5482-cb42-4aaa-80b5-3d0143fcead8
< 5.1
CRITICAL 9.8 The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi… — wordfence
8276ecfe-962b-4813-8011-4c8ca59d5389
< 1.5.3
CRITICAL 9.8 The Instant Image Generator (One Click Image Uploads from Pixabay, Pexels and OpenAI) plugin for WordPress is vulnerable… — wordfence
8247acc4-04dc-463a-906a-f6085116cf40
< 2.2.4
CRITICAL 9.8 The Zingiri Web Shop plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.2.3… — wordfence
82420667-9ba6-46ed-9a53-d16850755bb9
< 2.7.4
CRITICAL 9.8 The TI WooCommerce Wishlistplugin for WordPress is vulnerable to blind SQL Injection via the user_id parameter in versio… — wordfence
81fb9d43-3c27-4de9-aa2e-66b783c78fa2
< 1.2.6
CRITICAL 9.8 The Enzio - Responsive Business WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions up… — wordfence
81e7ab80-7df2-4ef4-80ee-a11d057151c4
< 1.2.0
CRITICAL 9.8 The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbi… — wordfence
81c62f9d-6a98-4f18-8c4a-c81c2730ce5d CRITICAL 9.8 The Ads Booster by Ads Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … — wordfence
81b44abb-6d30-4930-b68b-9a04d93f5169
< 2.1.0
CRITICAL 9.8 The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0… — wordfence
819b9565-2eb1-4b87-bf3a-5cd93429cafe
< 3.7.1.5
CRITICAL 9.8 The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form &… — wordfence
← Prev 52 53 54 55 56 57 58 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top