🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 61 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
740ed055-8548-42fd-81e1-9f63dda85374
< 3.8120
CRITICAL 9.8 The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to account takeover in all versions up to, a… — wordfence
73c98e25-98ae-48b8-9572-2d6a5dbbeb99
< 1.1.9
CRITICAL 9.8 The Medcity - Health & Medical WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to missin… — wordfence
73aa7b26-dbdf-4859-8fb9-f71dc734bb87
< 1.3
CRITICAL 9.8 SQL injection vulnerability in the "the_search_function" function in cardoza_ajax_search.php in the AJAX Post Search (ca… — wordfence
73a0d7a9-374b-430d-a7e5-3c7cdaff5785
< 1.4.3
CRITICAL 9.8 The Login As Users plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4… — wordfence
73837bb4-8af9-4455-93dc-522d64258014 CRITICAL 9.8 The BuddyPress Better Registration plugin for WordPress is vulnerable to authentication bypass in all versions up to, an… — wordfence
73835cfc-4c10-40d5-8df2-903d907326d4
< 1.9.5
CRITICAL 9.8 The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrat… — wordfence
73776e0a-4d2a-44f9-97a2-f06055ce2c63 CRITICAL 9.8 TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary… — wordfence
733ddf62-278b-4a2d-9dc5-28db3491cb29 CRITICAL 9.8 The moveto plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … — wordfence
7332fe2e-9bef-42b7-946e-4a2ee812ca26
< 2.0
CRITICAL 9.8 The ERE Recently Viewed plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… — wordfence
73251a74-5be3-446b-8e0a-ff2d1484c467
< 1.2.7
CRITICAL 9.8 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass T… — wordfence
73115c27-86f1-4421-9fe5-bf5d8cf54d9f CRITICAL 9.8 The WPLocalPlaces theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… — wordfence
72ed9cba-fe5c-4cee-9e1b-c3edde2521ca
< 9.0.3
CRITICAL 9.8 Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulner… — wordfence
72de9f64-f3e0-4705-adc1-6c22076b382f
< 5.4.8.2
CRITICAL 9.8 The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v… — wordfence
72aa362f-927d-427f-8de9-f5119d53497e
< 1.2.6
CRITICAL 9.8 The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions. — wordfence
72a179af-25a0-40f2-a585-8d25c0289782
< 0.9.2.7
CRITICAL 9.8 The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to privilege escalation via account takeover in … — wordfence
72633a5c-67e7-444f-9a32-ef3266468cee
< 1.2.78.0
CRITICAL 9.8 The MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. plugin for WordPress is vul… — wordfence
7250da0a-1ac6-48a6-a480-0721d604add3 CRITICAL 9.8 The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includ… — wordfence
72154404-f956-4ea2-96ec-166ade87885f
< 5.1.3
CRITICAL 9.8 The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2… — wordfence
71cc804f-6146-4594-8e7a-854754a1ff20
< 2.3.4
CRITICAL 9.8 The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… — wordfence
71955ba0-42ba-49a1-8b91-81069c6132ea
< 3.1.4
CRITICAL 9.8 A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePr… — wordfence
7192fb4c-0434-4e11-a2a7-c205b8d6b68e
< 1.2.9
CRITICAL 9.8 The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. Th… — wordfence
7183288f-47f1-477b-974d-e5e21c170d0f CRITICAL 9.8 SQL injection vulnerability in game_play.php in the FB Gorilla plugin for WordPress allows remote attackers to execute a… — wordfence
71625093-d813-43d9-95ec-d4ae0934abec
< 3.4.2
CRITICAL 9.8 The Wilmër theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.4.2. This makes it possible fo… — wordfence
715b0d61-1fac-4039-b18c-e9371788c24c
< 2.5.1
CRITICAL 9.8 A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitat… — wordfence
715723e7-5820-4a64-848f-f89b5b73a681
< 2.2.4
CRITICAL 9.8 The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versio… — wordfence
← Prev 58 59 60 61 62 63 64 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top