πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 63 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6ebffb82-7455-40c9-9ffd-b78e0e73e431
< 2.9.3
CRITICAL 9.8 The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file… — wordfence
6e954190-7c58-4044-a85e-a188fe5b6d89
< 8.4.2
CRITICAL 9.8 The Soledad theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 8.4.1 via de… — wordfence
6e5c6bf7-a653-4571-9566-574d2bb35c4f
< 1.2.6
CRITICAL 9.8 The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to… — wordfence
6e583ae8-40f7-4cd6-b72d-c47d8bec77d4
< 2.3.2
CRITICAL 9.8 The CheckView – Form & Checkout Testing plugin for WordPress is vulnerable to authorization bypass in all versions up … — wordfence
6e32ff58-e205-4c81-82d1-2a1048256747 CRITICAL 9.8 TheMailCWP plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'mail… — wordfence
6e2e294f-904b-4674-8baf-d3a9a260d634
< 2.20.4
CRITICAL 9.8 The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… — wordfence
6de3cbb4-61ac-443e-b7cf-5a2bfea25c56 CRITICAL 9.8 The photokit plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0. Thi… — wordfence
6dd6169b-bc94-4642-8975-2e96bc01576f
< 5.4.22
CRITICAL 9.8 The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21.… — wordfence
6d8916c7-0270-4159-8072-49b1d75a579e CRITICAL 9.8 The MaanStore API plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.… — wordfence
6d3bfb78-0538-4627-a206-8d8b5b200bc7
< 5.1.0.4
CRITICAL 9.8 The Custom Contact Forms plugin for WordPress is vulnerable to authentication bypass due to missing capability checks on… — wordfence
6d2a2460-fbac-41cd-9487-f83af0073de7
< 2.3.10
CRITICAL 9.8 The Besa theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.8. This makes i… — wordfence
6cf01a38-1fba-4c93-b3fa-acfdd5b19410
< 1.3
CRITICAL 9.8 The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.… — wordfence
6cecd06f-c064-49fd-b3fa-505a5a0c2e0b
< 2.4.10
CRITICAL 9.8 The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 v… — wordfence
6cc5f274-6e71-47a1-b4ec-9b3ba46fd7bf CRITICAL 9.8 The 123ContactForm plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the c… — wordfence
6cc3c124-f200-4d38-92b3-b520702f3a04
< 3.1.0
CRITICAL 9.8 The CouponXxL theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.0 via dese… — wordfence
6ca0ce12-4759-4182-b69e-665e189b92f7
< 3.1.2
CRITICAL 9.8 The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to PHP Object … — wordfence
6c8456fa-939c-4ceb-8361-a8758aec7708
< 2.9.0
CRITICAL 9.8 The TI WooCommerce Wishlist plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.… — wordfence
6c6a4c5f-7a02-4c53-a0ba-a2c7f592a3a8
< 2.3.3
CRITICAL 9.8 The Easy Digital Downloads – Simple Ecommerce for Selling Digital Files WordPress plugin was affected by a SQL Injecti… — wordfence
6c31d037-1f9e-4887-aaff-3c32fb8b4501
< 1.10.4
CRITICAL 9.8 The wp-hotel-booking plugin through 1.10.3 for WordPress allows remote attackers to execute arbitrary code because of an… — wordfence
6c31cf92-26b7-484d-8c93-ce241d655d07
< 260215
CRITICAL 9.8 The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and … — wordfence
6bf743b1-5a59-4e22-8c59-3c17b2646ec8
< 3.34
CRITICAL 9.8 The Store Locator Plugin for WordPress is vulnerable to blind SQL Injection via the sl_vars[num_initial_displayed] param… — wordfence
6bde6384-0fcc-4726-a7e5-bad6c3993bce
< 3.3.2
CRITICAL 9.8 The AccessAlly plugin for WordPress is vulnerable to Arbitrary Code Execution in versions before 3.3.2 via the login_err… — wordfence
6bb0462a-e801-4aa7-a98a-c5032cb8304c
< 9.9.7
CRITICAL 9.8 The plugin School Management Pro in version 8.9 contains code that allows an attacker to remotely execute code. — wordfence
6b8ba516-54f8-4422-846a-106b9e8bca8d
< 3.9.8
CRITICAL 9.8 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… — wordfence
6b7f700f-e40c-4b45-b651-ab1752255083 CRITICAL 9.8 SQL injection vulnerability in playlist.php in the Spiffy XSPF Player plugin 0.1 for WordPress allows remote attackers t… — wordfence
← Prev 60 61 62 63 64 65 66 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top