🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 62 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
71053df9-c4b6-4c27-9582-600363b82a36 CRITICAL 9.8 The WP Newsletter Subscription plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… — wordfence
70fb90f0-1ca4-41fe-8638-cdd05747adae CRITICAL 9.8 The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. … — wordfence
70f64ea0-5375-479f-90ac-29bcdf817cef
< 10.9.0
CRITICAL 9.8 The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable t… — wordfence
70ede219-e59d-40dd-9e5e-4f44089d7524
< 2.2.7
CRITICAL 9.8 Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6… — wordfence
70e29aa5-6f36-498f-ad85-f9d9ab8d9bcb CRITICAL 9.8 The sem-wysiwyg plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the… — wordfence
70dffb0a-eef0-4df7-977b-a36f937a4a89
< 1.9.0
CRITICAL 9.8 The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing ca… — wordfence
70a2b6ff-defc-4722-9af9-3cae94e98632
< 5.4.2
CRITICAL 9.8 The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up… — wordfence
708c2c69-aa1b-4bfb-bef5-f2faa1e49a10
< 1.5.31
CRITICAL 9.8 A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitat… — wordfence
7085e16a-cdf3-4467-b957-23ab372416e6
< 1.0.2
CRITICAL 9.8 SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.0.1 for WordPress allows remote attackers to ex… — wordfence
7053978d-4780-4532-b504-265b60d1911c
< 1.8.5
CRITICAL 9.8 The Makeaholic theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8.4. This m… — wordfence
70361501-8adc-499a-91d2-cf91fab5934a
< 2.0.7
CRITICAL 9.8 The 百度站长SEO合集(支持百度/神马/Bing/头条推送) plugin for WordPress is vulnerable to arbitrary file up… — wordfence
701d99b7-759f-4543-824d-dad84c35f5f3
< 1.1.65
CRITICAL 9.8 The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection via query parameter. — wordfence
7019b542-9b9a-4d16-94a0-412cccf1e6eb
< 5.3.9
CRITICAL 9.8 The XStore Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.3.8. … — wordfence
6ff01c24-fa35-43bc-be60-f2bb37854681
< 1.5.4
CRITICAL 9.8 The Doccure Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… — wordfence
6feae1c4-3735-4a33-85a5-867d458d2e8a
< 1.3.14
CRITICAL 9.8 The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclu… — wordfence
6fb01045-d38f-469f-8aaf-ff8882132acc
< 2.0.18
CRITICAL 9.8 The iThemes Sync plugin for WordPress is vulnerable to authentication bypass due to a missing validation on the secure k… — wordfence
6fa4aa8d-d7f1-4e91-bb2c-c9f80a4bb216
< 4.8.2
CRITICAL 9.8 The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.… — wordfence
6f9a6fc2-0375-480e-8c42-c6b97613bf68
< 0.9.2.9
CRITICAL 9.8 WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability — wordfence
6f9152fe-0273-4af3-8dee-ecb96ec7479b
< 1.3.1
CRITICAL 9.8 The Integration for Contact Form 7 and Zoho CRM, Bigin plugin for WordPress is vulnerable to PHP Object Injection in ver… — wordfence
6f89c43c-6729-40c5-bd32-3c328f83e366
< 6.2
CRITICAL 9.8 The RSVPMaker plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 6.1.9 due to… — wordfence
6f65d5c4-6f53-4836-9130-c9f4ed3be893
< 2.2.0
CRITICAL 9.8 The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization wi… — wordfence
6f476fc6-54c8-438f-ae6a-d29d1ffb4fbc CRITICAL 9.8 The Flexi – Guest Submit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … — wordfence
6f2cf7a3-5710-4db0-b75a-44d4073ee344 CRITICAL 9.8 The Affiliator plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.1.3.… — wordfence
6f25b0cc-60ec-49a0-8356-fd3fba97e987
< 4.5.0
CRITICAL 9.8 The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all ver… — wordfence
6ec02202-18e3-4a57-be2c-7dbf50e500dc
< 4.1.1
CRITICAL 9.8 The MainWP File Uploader Extension for WordPress is vulnerable to arbitrary file uploads in versions up to, and includin… — wordfence
← Prev 59 60 61 62 63 64 65 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top