🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 60 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6de3cbb4-61ac-443e-b7cf-5a2bfea25c56 CRITICAL 9.8 The photokit plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0. Thi… wordfence
6dd6169b-bc94-4642-8975-2e96bc01576f
< 5.4.22
CRITICAL 9.8 The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21.… wordfence
6d8916c7-0270-4159-8072-49b1d75a579e CRITICAL 9.8 The MaanStore API plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.… wordfence
6d3bfb78-0538-4627-a206-8d8b5b200bc7
< 5.1.0.4
CRITICAL 9.8 The Custom Contact Forms plugin for WordPress is vulnerable to authentication bypass due to missing capability checks on… wordfence
6d2a2460-fbac-41cd-9487-f83af0073de7
< 2.3.10
CRITICAL 9.8 The Besa theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.8. This makes i… wordfence
6cf01a38-1fba-4c93-b3fa-acfdd5b19410
< 1.3
CRITICAL 9.8 The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.… wordfence
6cecd06f-c064-49fd-b3fa-505a5a0c2e0b
< 2.4.10
CRITICAL 9.8 The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 v… wordfence
6cc5f274-6e71-47a1-b4ec-9b3ba46fd7bf CRITICAL 9.8 The 123ContactForm plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the c… wordfence
6cc3c124-f200-4d38-92b3-b520702f3a04
< 3.1.0
CRITICAL 9.8 The CouponXxL theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.0 via dese… wordfence
6ca0ce12-4759-4182-b69e-665e189b92f7
< 3.1.2
CRITICAL 9.8 The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to PHP Object … wordfence
6c8456fa-939c-4ceb-8361-a8758aec7708
< 2.9.0
CRITICAL 9.8 The TI WooCommerce Wishlist plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.… wordfence
6c6a4c5f-7a02-4c53-a0ba-a2c7f592a3a8
< 2.3.3
CRITICAL 9.8 The Easy Digital Downloads – Simple Ecommerce for Selling Digital Files WordPress plugin was affected by a SQL Injecti… wordfence
6c31d037-1f9e-4887-aaff-3c32fb8b4501
< 1.10.4
CRITICAL 9.8 The wp-hotel-booking plugin through 1.10.3 for WordPress allows remote attackers to execute arbitrary code because of an… wordfence
6c31cf92-26b7-484d-8c93-ce241d655d07
< 260215
CRITICAL 9.8 The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and … wordfence
6bf743b1-5a59-4e22-8c59-3c17b2646ec8
< 3.34
CRITICAL 9.8 The Store Locator Plugin for WordPress is vulnerable to blind SQL Injection via the sl_vars[num_initial_displayed] param… wordfence
6bde6384-0fcc-4726-a7e5-bad6c3993bce
< 3.3.2
CRITICAL 9.8 The AccessAlly plugin for WordPress is vulnerable to Arbitrary Code Execution in versions before 3.3.2 via the login_err… wordfence
6bb0462a-e801-4aa7-a98a-c5032cb8304c
< 9.9.7
CRITICAL 9.8 The plugin School Management Pro in version 8.9 contains code that allows an attacker to remotely execute code. wordfence
6b7f700f-e40c-4b45-b651-ab1752255083 CRITICAL 9.8 SQL injection vulnerability in playlist.php in the Spiffy XSPF Player plugin 0.1 for WordPress allows remote attackers t… wordfence
6b558818-f459-4bc1-893c-8c1c7bf9d6d2
< 3.7.22
CRITICAL 9.8 Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus di… wordfence
6b5288db-8996-4363-bdc0-d3bdd2445e9f CRITICAL 9.8 The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Remote Code Exec… wordfence
6b48cae6-254c-4882-a464-3a44a63cadf5
< 3.16.12
CRITICAL 9.8 The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter… wordfence
6b456815-ffdf-41fb-b4a8-0f22fd059d34 CRITICAL 9.8 The AJAX Store Locator plugin for WordPress is vulnerable to SQL Injection via the ‘StoreLocation’ parameter in vers… wordfence
6b443610-416c-41d6-9449-9e20f719af06 CRITICAL 9.8 The Contus Video Gallery plugin for WordPress is vulnerable to Arbitrary File Upload due to missing file type validation… wordfence
6b431493-fd96-495b-aaa7-6dfeef04b011
< 3.7.1
CRITICAL 9.8 The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement v… wordfence
6b26f41e-fab8-4fe4-b5ab-4c238a433eab CRITICAL 9.8 The User registration & user profile – UserPlus plugin for WordPress is vulnerable to privilege escalation in all vers… wordfence
← Prev 57 58 59 60 61 62 63 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top