🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 56 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7bb7ee83-f75a-4f19-8595-f5cf2ee97ae0 CRITICAL 9.8 SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to… wordfence
7bae3acf-bbb3-4b10-b46f-8086240a2f02 CRITICAL 9.8 The Mukioplayer For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘cid’ parameter in version… wordfence
7b738676-250d-4af4-81ff-cee9efcf996e
< 1.0.1
CRITICAL 9.8 The NewStatPress plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 1.0.0 due… wordfence
7b5e5b0a-dd6a-401f-86db-940b3386ed21
< 5.6.0
CRITICAL 9.8 The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection. wordfence
7b110a6c-fd6d-4c00-bdd6-08fce116b937
< 2.2.1
CRITICAL 9.8 The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of … wordfence
7af05793-b495-4cad-842b-f168d0dc8253 CRITICAL 9.8 The Analytics Stats Counter Statistics plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and… wordfence
7ad16d1e-e778-4cb4-a15d-ddb906f27762
< 7.1.9.8
CRITICAL 9.8 The Checkout Mestres WP plugin for WordPress is vulnerable to authentication due to a weak password reset functionality … wordfence
7ab50032-abc0-4160-b9ad-369da67ef79a
< 8.4.6.1
CRITICAL 9.8 The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Authentication Bypass in all … wordfence
7a5acdeb-0aef-4124-bb18-43587a032206 CRITICAL 9.8 The Picsmize plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ver… wordfence
7a44873c-5f14-4ff5-85ed-a6575aaa9347 CRITICAL 9.8 The Felici theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'uploa… wordfence
7a3e89cc-56cb-42d7-b4f6-bfc7ca0e03e6
< 2.8.2
CRITICAL 9.8 The JS Help Desk – Best Help Desk & Support Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘emai… wordfence
7a116f28-a560-4b54-9cd1-f1dd9ac3238d
< 1.4.8
CRITICAL 9.8 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in … wordfence
7a09288c-b8de-4674-9f96-d26ff3c7d917
< 2.8.0
CRITICAL 9.8 The Bit Form Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation … wordfence
79f14b3f-3163-41c2-88ff-a1e0879e8248
< 5.8
CRITICAL 9.8 The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to SQL Injection via the 'refUrl' param… wordfence
79d0e247-18f3-4e98-b24e-336a17276b7e
< 4.0.0
CRITICAL 9.8 The Bootscraper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.0. This… wordfence
79b631a0-08a7-460f-8668-0b10b42f12d7
< 1.0.1
CRITICAL 9.8 The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to SQL Injection via an unknown… wordfence
79b0a90b-5b75-4757-bd7b-909350f54175
< 5.3.6
CRITICAL 9.8 A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute… wordfence
78e604e8-42f3-4c53-a59a-86a49043bde1 CRITICAL 9.8 The Feed Comments Number plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… wordfence
78c1308b-0849-4235-b2d6-0b1750a5614f
< 3.2.6
CRITICAL 9.8 The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and … wordfence
789670b1-8cc3-4b66-87e3-a0da6fbd2706
< 3.8116
CRITICAL 9.8 The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil… wordfence
7889e071-84a8-46ec-abe5-5c98980ce275
< 2.0.0
CRITICAL 9.8 The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests'… wordfence
78759abf-4584-4beb-9ae7-39a5c3fe4b75
< 4.2.5
CRITICAL 9.8 The YARPP – Yet Another Related Posts Plugin for WordPress is vulnerable a Cross-Site Request Forgery which can lead t… wordfence
7867d651-dd15-4d91-a7ca-65f49cb94b65
< 1.0.9
CRITICAL 9.8 The Search Autocomplete plugin for WordPress is vulnerable to SQL Injection via the ‘term’ parameter in versions bef… wordfence
7857571c-182f-4072-8cae-8b0c1b3a9d31 CRITICAL 9.8 The IDonate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.9. This mak… wordfence
781b4122-e3a0-465f-936c-4996577a3c40 CRITICAL 9.8 The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to m… wordfence
← Prev 53 54 55 56 57 58 59 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top