πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 62 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
68dd9f6f-ccee-4a27-bd21-2fb32b92cc62
< 6.0.7.2
CRITICAL 9.8 The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6… wordfence
68ae048c-a897-4061-b839-56ca0dbb2581
< 3.0
CRITICAL 9.8 The kineticPay for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… wordfence
689e86c4-5330-4837-b3ff-2553fa1c2ead
< 3.1.1
CRITICAL 9.8 The Global DNS plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.0. … wordfence
6843939b-889f-45d7-9758-4b76a20d15f1 CRITICAL 9.8 The Dynamic Font Replacement DFR4WP EN plugin for WordPress is vulnerable to arbitrary file deletion in versions up to ,… wordfence
6837b91d-b3ba-435a-965b-fa18d9b9b9c8
< 9.2.7
CRITICAL 9.8 The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame… wordfence
68052614-204f-4237-af0e-4b8210ebd59f
< 5.15.2
CRITICAL 9.8 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, a… wordfence
67df10cc-ce3c-4157-9860-7e367062f710 CRITICAL 9.8 The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remo… wordfence
67d8dc60-e66e-4f2f-a06d-f95375ca1994 CRITICAL 9.8 The WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. plugin for WordPress is vulnerable to arbitrar… wordfence
67c7e67e-3e68-4f49-9d81-fa0ed451376e
< 1.7.0
CRITICAL 9.8 The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more … wordfence
67c4066f-b8bc-4cd0-ae47-844af23e003f CRITICAL 9.8 The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including… wordfence
67b152b5-e662-4dbd-a7db-87fc63cfb307
< 2.1.1
CRITICAL 9.8 TheTop Quark Architecture plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
67890f13-df93-4c1d-aabe-a90437183bbd
< 2.20.1
CRITICAL 9.8 The Masteriyo LMS PRO plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2… wordfence
672edfd2-ca4b-4937-8237-3c0a4acc8690 CRITICAL 9.8 The pb-embedFlash plugin for WordPress is vulnerable to Remote File Inclusion with media files in versions up to, and in… wordfence
6711f542-8b75-4968-86ac-9686ded775b7
< 2.1.2
CRITICAL 9.8 Version 2.1.1 of WordPress was injected with malicious code that supplied attackers with backdoor access to WordPress si… wordfence
66ce2d12-8f57-4140-b3cf-0fc8c1c4f3d5
< 1.1.8
CRITICAL 9.8 SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar pl… wordfence
66c20a71-96e2-4d5e-a2ed-7e7afbe85306 CRITICAL 9.8 The Automatic Translation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
66a6569b-88ec-42d8-8396-6e62f1c51b24 CRITICAL 9.8 The Invit0r plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the ofc… wordfence
66969472-4b3c-4d56-b761-523ea854e3db
< 1.5.8
CRITICAL 9.8 The Leaflet Maps Marker Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
668ba3a9-d53c-45ab-854f-1a9e83dd54b8
< 1.6.7
CRITICAL 9.8 The WP e-Commerce – Store Exporter plugin for WordPress is vulnerable to authorization bypass due to a missing capabil… wordfence
6687ebbe-fdf4-4ecb-bf59-034bb4b0104c
< 3.5.1
CRITICAL 9.8 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege… wordfence
66845165-02c7-4f4a-93fd-1a309fb7b386 CRITICAL 9.8 The CAFEHAUS API plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, … wordfence
66749606-e76f-41fb-bcf1-c06681de2ee3 CRITICAL 9.8 The Master Slider Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3… wordfence
664e6e2a-faa1-4609-b250-d7e94c5d5a04
< 1.6.3
CRITICAL 9.8 The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… wordfence
6629e1a9-3b28-4c8c-95d4-3c0011a7364a
< 2.1.5
CRITICAL 9.8 An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_no… wordfence
661d4ea9-572d-4544-b5cf-39fd69c104a6
< 3.9.8
CRITICAL 9.8 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… wordfence
← Prev 59 60 61 62 63 64 65 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top