🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 58 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7d70e56f-3bb2-4cfd-8998-e419bbdf016c CRITICAL 9.8 The Meetup plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1. This i… — wordfence
7d636768-37b4-4343-9028-30e7b1f997f2
< 3.0.0.266
CRITICAL 9.8 The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080… — wordfence
7d5f2f1c-e93d-4fc5-bf1b-2f18996f2b5b
< 1.3.6
CRITICAL 9.8 The Kiamo - Responsive Business Service WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in ver… — wordfence
7d5d05ad-1a7a-43d2-bbbf-597e975446be
< 9.1.2
CRITICAL 9.8 The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass … — wordfence
7d1cc8c4-6c14-4d0c-9420-02d709f88b2f
< 3.9.9
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.9.8 due to… — wordfence
7d0919de-dac5-4168-aae4-74bf528a27e4
< 1.4.5
CRITICAL 9.8 The GravityWP - Merge Tags plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … — wordfence
7cf05767-af07-4577-9f00-b2695237e041
< 1.48
CRITICAL 9.8 The FluentBoards plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.47 via d… — wordfence
7cdfce88-b6c2-4820-9d6f-446f61b9b596
< 1.2.85
CRITICAL 9.8 The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is du… — wordfence
7cd8dc3e-6328-49f2-8cc7-cc395646ee40 CRITICAL 9.8 The Zenny theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.5. This makes … — wordfence
7cce9b8b-0589-4b09-b184-a66fc86fcb46
< 2.7.10
CRITICAL 9.8 The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including,… — wordfence
7ca93715-bcc4-4710-bfda-f1774fc66cbe CRITICAL 9.8 The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and in… — wordfence
7ca2c82d-0962-4e18-83d7-636bcef18ca5 CRITICAL 9.8 The Dash theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3 via deserializa… — wordfence
7c7ad744-949c-4a27-81c9-b2badbaa1eec
< 4.2.4
CRITICAL 9.8 The Greenmart theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.3. This ma… — wordfence
7c6be4e1-1b24-4a95-a6fd-3196f47796a6 CRITICAL 9.8 The TDO Mini Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via … — wordfence
7c5092fa-a2ea-4a84-8ebd-273faf6c8707
< 1.2
CRITICAL 9.8 The Kish Guest Posting plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … — wordfence
7c48a2dc-65d8-4fc5-9ee2-70c6a78611e6 CRITICAL 9.8 The Critical Site Intel plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to… — wordfence
7c3ae610-44ef-4354-b085-00c00a486dc9
< 1.4.7
CRITICAL 9.8 The Login with Cognito plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 1.4.… — wordfence
7c31d9b3-38b1-49a1-b361-ffe97e02bff0
< 2.4
CRITICAL 9.8 The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to mis… — wordfence
7c1388d2-ba60-4738-94d6-31123ef64ef8
< 3.6.6
CRITICAL 9.8 The Course Builder - Online Course WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all vers… — wordfence
7c1372bd-821d-439c-9b11-dfa5f08dd0dd
< 2.34.0
CRITICAL 9.8 The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … — wordfence
7bfe87cf-9883-4f8f-a0f5-23bbc7bb9b7c
< 2.20
CRITICAL 9.8 The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.19. This is d… — wordfence
7bcd9611-8f1e-42da-a47b-abcbe0cfd849
< 4.0.1
CRITICAL 9.8 The News & Blog Designer Pack plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… — wordfence
7bc33a05-d462-492e-9ea5-cf37b887cc94
< 2.0.0
CRITICAL 9.8 The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… — wordfence
7bb7ee83-f75a-4f19-8595-f5cf2ee97ae0 CRITICAL 9.8 SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to… — wordfence
7bae3acf-bbb3-4b10-b46f-8086240a2f02 CRITICAL 9.8 The Mukioplayer For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘cid’ parameter in version… — wordfence
← Prev 55 56 57 58 59 60 61 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top