ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 59 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
70dffb0a-eef0-4df7-977b-a36f937a4a89
< 1.9.0
CRITICAL 9.8 The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing ca… wordfence
70a2b6ff-defc-4722-9af9-3cae94e98632
< 5.4.2
CRITICAL 9.8 The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up… wordfence
708c2c69-aa1b-4bfb-bef5-f2faa1e49a10
< 1.5.31
CRITICAL 9.8 A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitat… wordfence
7085e16a-cdf3-4467-b957-23ab372416e6
< 1.0.2
CRITICAL 9.8 SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.0.1 for WordPress allows remote attackers to ex… wordfence
7053978d-4780-4532-b504-265b60d1911c
< 1.8.5
CRITICAL 9.8 The Makeaholic theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8.4. This m… wordfence
70361501-8adc-499a-91d2-cf91fab5934a
< 2.0.7
CRITICAL 9.8 The 百度站长SEOåˆé›†(支æŒç™¾åº¦/神马/Bing/å¤´æ¡æŽ¨é€) plugin for WordPress is vulnerable to arbitrary file up… wordfence
701d99b7-759f-4543-824d-dad84c35f5f3
< 1.1.65
CRITICAL 9.8 The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection via query parameter. wordfence
7019b542-9b9a-4d16-94a0-412cccf1e6eb
< 5.3.9
CRITICAL 9.8 The XStore Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.3.8. … wordfence
6ff01c24-fa35-43bc-be60-f2bb37854681
< 1.5.4
CRITICAL 9.8 The Doccure Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… wordfence
6feae1c4-3735-4a33-85a5-867d458d2e8a
< 1.3.14
CRITICAL 9.8 The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclu… wordfence
6fb01045-d38f-469f-8aaf-ff8882132acc
< 2.0.18
CRITICAL 9.8 The iThemes Sync plugin for WordPress is vulnerable to authentication bypass due to a missing validation on the secure k… wordfence
6fa4aa8d-d7f1-4e91-bb2c-c9f80a4bb216
< 4.8.2
CRITICAL 9.8 The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.… wordfence
6f9a6fc2-0375-480e-8c42-c6b97613bf68
< 0.9.2.9
CRITICAL 9.8 WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability wordfence
6f9152fe-0273-4af3-8dee-ecb96ec7479b
< 1.3.1
CRITICAL 9.8 The Integration for Contact Form 7 and Zoho CRM, Bigin plugin for WordPress is vulnerable to PHP Object Injection in ver… wordfence
6f89c43c-6729-40c5-bd32-3c328f83e366
< 6.2
CRITICAL 9.8 The RSVPMaker plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 6.1.9 due to… wordfence
6f65d5c4-6f53-4836-9130-c9f4ed3be893
< 2.2.0
CRITICAL 9.8 The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization wi… wordfence
6f476fc6-54c8-438f-ae6a-d29d1ffb4fbc CRITICAL 9.8 The Flexi – Guest Submit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … wordfence
6f2cf7a3-5710-4db0-b75a-44d4073ee344 CRITICAL 9.8 The Affiliator plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.1.3.… wordfence
6f25b0cc-60ec-49a0-8356-fd3fba97e987
< 4.5.0
CRITICAL 9.8 The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all ver… wordfence
6ec02202-18e3-4a57-be2c-7dbf50e500dc
< 4.1.1
CRITICAL 9.8 The MainWP File Uploader Extension for WordPress is vulnerable to arbitrary file uploads in versions up to, and includin… wordfence
6ebffb82-7455-40c9-9ffd-b78e0e73e431
< 2.9.3
CRITICAL 9.8 The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file… wordfence
6e954190-7c58-4044-a85e-a188fe5b6d89
< 8.4.2
CRITICAL 9.8 The Soledad theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 8.4.1 via de… wordfence
6e5c6bf7-a653-4571-9566-574d2bb35c4f
< 1.2.6
CRITICAL 9.8 The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to… wordfence
6e32ff58-e205-4c81-82d1-2a1048256747 CRITICAL 9.8 TheMailCWP plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'mail… wordfence
6e2e294f-904b-4674-8baf-d3a9a260d634
< 2.20.4
CRITICAL 9.8 The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
← Prev 56 57 58 59 60 61 62 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top