πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 6 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
83e5a0dc-fc51-4565-945f-190cf9175874 CRITICAL 9.9 The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and … wordfence
83189c51-2605-4808-a0fa-3e5245cc0806
< 9.4.5
CRITICAL 9.9 The WordPress Tooltips plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 9.4.3 d… wordfence
80f7e161-b071-4cb1-8080-ff0ad926a5ca
< 8.6.03.005
CRITICAL 9.9 The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
7f3dac5a-9ff8-4e8c-8c73-422123e121d8
< 1.3.24
CRITICAL 9.9 The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all … wordfence
7e52882e-d86f-4863-bdb6-e33c0449d14c
< 3.0.0
CRITICAL 9.9 PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, whic… wordfence
7aa62be9-93b9-423f-89f8-809ca0035547
< 3.0.0
CRITICAL 9.9 PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg blo… wordfence
79fb4f24-8a59-4e57-b583-c87ee2493cdb
< 21.3.5
CRITICAL 9.9 The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordP… wordfence
7832f8fe-2b41-4cfb-a734-db4ec88d91a3
< 2.6.8
CRITICAL 9.9 The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
71105a3c-4eb7-49b4-ba47-7997ddeb62c3
< 2.3.62
CRITICAL 9.9 The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the geodir_total_listings_count function in ver… wordfence
70e6a0b9-5bf2-4d0b-976e-6d5c56dff37c
< 1.2.8
CRITICAL 9.9 The Zoho Marketing Automation plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.… wordfence
6fed4181-400b-4414-aa50-1e7bc92d542f
< 1.3.5.3
CRITICAL 9.9 The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution i… wordfence
6d9f5901-dc11-4877-b753-deb9c03f4a4e
< 1.6.2
CRITICAL 9.9 The Zita Elementor Site Library plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability… wordfence
6bef7dcd-920b-4aee-b227-c7eec9fe73fc
< 1.1.13
CRITICAL 9.9 The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to arbitrary file uploads due to … wordfence
6bd03b86-e9b7-44d5-9528-efd94f0f79f5
< 4.2.2
CRITICAL 9.9 The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin plugin for WordPress is … wordfence
63d0cb9b-e6ac-474e-ac6b-c0cbd14a19bd
< 3.6.11
CRITICAL 9.9 The DirectoryPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.10 due to i… wordfence
5d8e3832-b3ed-4687-94d8-8ba2c832584c CRITICAL 9.9 The SP Project & Document Manager plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all ve… wordfence
53c9d3d0-5fea-4e36-b356-8d3c0e672cac
< 2.10.3
CRITICAL 9.9 Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders f… wordfence
491240c5-2045-4e0b-9916-4337946d2653
< 1.4.12
CRITICAL 9.9 The WordPress PDF Light Viewer Plugin WordPress plugin before 1.4.12 allows users with Author roles to execute arbitrary… wordfence
466eec4a-8aac-4b0d-ba18-9667aa70de5a CRITICAL 9.9 The Find Duplicates plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.6 due to i… wordfence
4257d4ca-0e92-4d2f-b65b-dff9d7d48cb8
< 3.7.5
CRITICAL 9.9 The Easy Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.4 due to… wordfence
4174b47a-75d0-4ada-bd4d-efbaf0b1a049
< 3.2.7
CRITICAL 9.9 The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in version… wordfence
4167f0ad-aeef-4525-82c9-336f9f48a55e
< 5.3.9
CRITICAL 9.9 The XStore Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … wordfence
41395c95-230d-441a-a261-cd67b95b76e3
< 7.19.3
CRITICAL 9.9 The Element Pack Pro - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Directory… wordfence
3ec997c8-3f47-45c8-8fa2-019b01c97c94
< 2.9.4
CRITICAL 9.9 An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in … wordfence
3d8b4bb6-3715-40c1-8140-7fcf874ccec3 CRITICAL 9.9 The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and incl… wordfence
← Prev 3 4 5 6 7 8 9 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top