🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 58 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
73aa7b26-dbdf-4859-8fb9-f71dc734bb87
< 1.3
CRITICAL 9.8 SQL injection vulnerability in the "the_search_function" function in cardoza_ajax_search.php in the AJAX Post Search (ca… wordfence
73a0d7a9-374b-430d-a7e5-3c7cdaff5785
< 1.4.3
CRITICAL 9.8 The Login As Users plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4… wordfence
73837bb4-8af9-4455-93dc-522d64258014 CRITICAL 9.8 The BuddyPress Better Registration plugin for WordPress is vulnerable to authentication bypass in all versions up to, an… wordfence
73835cfc-4c10-40d5-8df2-903d907326d4
< 1.9.5
CRITICAL 9.8 The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrat… wordfence
73776e0a-4d2a-44f9-97a2-f06055ce2c63 CRITICAL 9.8 TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary… wordfence
733ddf62-278b-4a2d-9dc5-28db3491cb29 CRITICAL 9.8 The moveto plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
7332fe2e-9bef-42b7-946e-4a2ee812ca26
< 2.0
CRITICAL 9.8 The ERE Recently Viewed plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… wordfence
73115c27-86f1-4421-9fe5-bf5d8cf54d9f CRITICAL 9.8 The WPLocalPlaces theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… wordfence
72ed9cba-fe5c-4cee-9e1b-c3edde2521ca
< 9.0.3
CRITICAL 9.8 Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulner… wordfence
72de9f64-f3e0-4705-adc1-6c22076b382f
< 5.4.8.2
CRITICAL 9.8 The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v… wordfence
72aa362f-927d-427f-8de9-f5119d53497e
< 1.2.6
CRITICAL 9.8 The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions. wordfence
72633a5c-67e7-444f-9a32-ef3266468cee
< 1.2.78.0
CRITICAL 9.8 The MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. plugin for WordPress is vul… wordfence
7250da0a-1ac6-48a6-a480-0721d604add3 CRITICAL 9.8 The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includ… wordfence
72154404-f956-4ea2-96ec-166ade87885f
< 5.1.3
CRITICAL 9.8 The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2… wordfence
71cc804f-6146-4594-8e7a-854754a1ff20
< 2.3.4
CRITICAL 9.8 The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
71955ba0-42ba-49a1-8b91-81069c6132ea
< 3.1.4
CRITICAL 9.8 A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePr… wordfence
7192fb4c-0434-4e11-a2a7-c205b8d6b68e
< 1.2.9
CRITICAL 9.8 The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. Th… wordfence
7183288f-47f1-477b-974d-e5e21c170d0f CRITICAL 9.8 SQL injection vulnerability in game_play.php in the FB Gorilla plugin for WordPress allows remote attackers to execute a… wordfence
71625093-d813-43d9-95ec-d4ae0934abec
< 3.4.2
CRITICAL 9.8 The Wilmër theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.4.2. This makes it possible fo… wordfence
715b0d61-1fac-4039-b18c-e9371788c24c
< 2.5.1
CRITICAL 9.8 A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitat… wordfence
71053df9-c4b6-4c27-9582-600363b82a36 CRITICAL 9.8 The WP Newsletter Subscription plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… wordfence
70fb90f0-1ca4-41fe-8638-cdd05747adae CRITICAL 9.8 The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. … wordfence
70f64ea0-5375-479f-90ac-29bcdf817cef CRITICAL 9.8 The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable t… wordfence
70ede219-e59d-40dd-9e5e-4f44089d7524
< 2.2.7
CRITICAL 9.8 Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6… wordfence
70e29aa5-6f36-498f-ad85-f9d9ab8d9bcb CRITICAL 9.8 The sem-wysiwyg plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the… wordfence
← Prev 55 56 57 58 59 60 61 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top