ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 63 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
65fc2929-b65b-451b-b90d-6739a673ac16 CRITICAL 9.8 The MBStore - Digital WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions … wordfence
65ebc744-6cc2-47ce-b225-81820e49d59c
< 1.6.0
CRITICAL 9.8 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versio… wordfence
65e2e9e3-2778-4baf-8269-fc13d5ef1212
< 2.7.2
CRITICAL 9.8 The JS Help Desk plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.7.1. T… wordfence
65be9417-7029-4f34-b834-98208a42743b
< 8.0.0
CRITICAL 9.8 The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to… wordfence
65988550-d39d-40be-8d25-647e7237062d
< 6.1.1
CRITICAL 9.8 The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all ver… wordfence
657f3bd7-2cdc-4eb6-ba50-7c7fca468df0
< 5.0.13
CRITICAL 9.8 The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and… wordfence
65386d2b-5d0c-4e49-a79a-a793b4b599e0 CRITICAL 9.8 The FW Food Menu – Responsive food menu with ordering & delivery solutions plugin for WordPress is vulnerable to arbit… wordfence
65192fdb-86db-475a-8c61-4db922920cfe
< 250214
CRITICAL 9.8 The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216… wordfence
65166432-a877-4070-94c1-cdaf7e5d7586
< 1.5.99
CRITICAL 9.8 The Booking Package plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including 1.5.98 d… wordfence
64eb4bfe-09b4-43c7-9d7e-f14fc5edf3c1
< 6.90
CRITICAL 9.8 The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in … wordfence
64e806df-4919-4a58-8f21-075f09668174
< 1.0.73
CRITICAL 9.8 The 10Web Map Builder for Google Maps plugin for WordPress is vulnerable to generic SQL Injection via the multiple param… wordfence
64e125c7-3f1e-43ed-8655-e0fbb95bc84b CRITICAL 9.8 The "CStar Design WordPress Theme" theme for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in vers… wordfence
6494e54c-db04-41f9-8b91-6ad12528cf01
< 3.1.17
CRITICAL 9.8 The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… wordfence
647cc71d-4d3a-4722-b498-baaee2450809
< 10.6.7
CRITICAL 9.8 The RSVPMaker plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 10.6.6 via de… wordfence
647a2f27-092a-4db1-932d-87ae8c2efcca CRITICAL 9.8 The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via… wordfence
643d41b9-f949-4fc1-acb4-d3147b59823b CRITICAL 9.8 The Goodlayers Hotel plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.1.4 … wordfence
64188179-1d7d-476f-866c-62bc10c85a3d
< 2.3.1
CRITICAL 9.8 The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admi… wordfence
641123af-1ec6-4549-a58c-0a08b4678f45
< 5.7.21
CRITICAL 9.8 The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ paramete… wordfence
640f2616-f3a5-4be6-901e-848d2d77506e
< 2.7.8
CRITICAL 9.8 The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archiv… wordfence
64087631-3514-4fec-ad2f-b095d7c727bd
< 2.8.3
CRITICAL 9.8 The Houzez theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.8.2 due to insufficie… wordfence
63fab608-1a75-4b07-8d82-8ab87e197547 CRITICAL 9.8 The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions… wordfence
63f3aa9e-2d82-440b-b37c-211dc3b5d26d
< 3.3.4
CRITICAL 9.8 The Chaty Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ve… wordfence
63f10214-69ef-4b5d-8d2b-2e2c1bafa7e7
< 1.9.4.5
CRITICAL 9.8 The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in in… wordfence
63effbe3-e509-4f62-a7aa-7727e855bebf CRITICAL 9.8 The Wp2android plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~… wordfence
63c74d96-84da-408f-ba2c-cde0ff108bf1
< 3.4.9
CRITICAL 9.8 The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to re… wordfence
← Prev 60 61 62 63 64 65 66 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top