🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 61 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6b15eca5-fd47-4f8f-8ade-3a90e0bfc110
< 7.3.2
CRITICAL 9.8 The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, a… wordfence
6afbdac4-e52a-4ad3-a99a-2d75e698e0fc
< 2.9.3
CRITICAL 9.8 The JS Help Desk plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.9.2. Thi… wordfence
6aef6fbb-be8c-49e1-ada5-7b4aa8b2ff72
< 1.3.2
CRITICAL 9.8 The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication B… wordfence
6aeb0352-66ab-45d4-ad61-f425d7d41f45 CRITICAL 9.8 The Daily Edition theme for WordPress is vulnerable to SQL Injection via the ‘&id’ parameter in versions up to, and … wordfence
6abbdecd-782a-44a2-981a-ae6caa50dd6a CRITICAL 9.8 The Article analytics plugin for WordPress is vulnerable to SQL Injection via the 'p' parameter in all versions up to, a… wordfence
6ab975b0-4216-46df-bf5e-91e403728e5b
< 1.5.4
CRITICAL 9.8 The wpDataTables plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… wordfence
6ab578cd-3a0b-43d3-aaa7-0a01f431a4e2
< 4.2.5.8
CRITICAL 9.8 The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all ve… wordfence
6ab0d342-bfa7-4760-b839-37c3354414ca CRITICAL 9.8 The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5… wordfence
6a7e794b-aa0e-4db3-8999-c9c5134a4ded CRITICAL 9.8 The eTemplates plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.2.1 due to insuff… wordfence
6a60e2c3-4597-4b21-ad20-6a00e483fcf1
< 16.6
CRITICAL 9.8 The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… wordfence
6a4d5a40-2ec0-468e-bafb-a713629f6006
< 4.51
CRITICAL 9.8 The Webcam Video Conference plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
6a0be61b-a1ee-499f-b991-58d5494bce18
< 1.0.1
CRITICAL 9.8 The Zendrop – Global Dropshipping plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and … wordfence
6a050764-0ba6-49a4-bd71-f79e3129fc4c
< 2.9.9
CRITICAL 9.8 The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to mis… wordfence
6a04e6ad-9365-4cb5-a0a0-82e047647d6b
< 4.2.9
CRITICAL 9.8 The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modi… wordfence
69b2f126-8f57-4bea-b0e9-14b4566ac470
< 2.0.3
CRITICAL 9.8 The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection via the 'orderby' and 'order' parameters. wordfence
6989e54b-ce5e-4c79-bd0d-0f7978a4bd44
< 4.6.1
CRITICAL 9.8 The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?pag… wordfence
6980248b-195d-4e03-853e-a767a9a4b513 CRITICAL 9.8 The Partners plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.2.0 via dese… wordfence
6980112b-a555-47a4-b2d7-f0187d52fc63
< 1.2.4
CRITICAL 9.8 The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to … wordfence
6969d281-f280-4714-9859-38ac66e9cc60
< 3.0.6
CRITICAL 9.8 The Edwiser Bridge plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5. … wordfence
695819e6-2574-4047-a55d-a78289c29ba0
< 1.5.55
CRITICAL 9.8 Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL inje… wordfence
694b67d2-7d60-4764-a2c0-02698c331772
< 3.8.1
CRITICAL 9.8 The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 vi… wordfence
692a5838-4a32-4444-b1a0-018fa25594a9
< 2.0.2
CRITICAL 9.8 The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… wordfence
68ed894d-b48b-42ef-89a9-b6a2ea093fc4
< 1.4
CRITICAL 9.8 The Custom Fields Account Registration For Woocommerce plugin for WordPress is vulnerable to Privilege Escalation in all… wordfence
68e838d4-2ff2-4925-b2ff-ba3f7b379010
< 3.1.4
CRITICAL 9.8 A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress Word… wordfence
68e0f54d-08ec-4e41-ac9b-d72cdde5a724 CRITICAL 9.8 The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the… wordfence
← Prev 58 59 60 61 62 63 64 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top