🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 64 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
63ab6b17-360d-49b2-b1b5-652629eba3be CRITICAL 9.8 The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to Privilege Escalation in all versions u… wordfence
6347f588-a3fd-4909-ad57-9d78787b5728
< 2.1.2
CRITICAL 9.8 The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to … wordfence
6345d360-5f58-44d2-bc2d-1a20ee43e146
< 3.7.35
CRITICAL 9.8 Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been p… wordfence
634303eb-b120-4384-9780-b950de491099 CRITICAL 9.8 The µAudio Player plugin for WordPress is vulnerable to Remote File Inclusion of image files in versions up to, and inc… wordfence
63388bb5-42f1-40c9-ac01-3ab6fc242106 CRITICAL 9.8 The postMash Custom – custom post order plugin for WordPress is vulnerable to SQL Injection in versions up to, and inc… wordfence
62bc53ae-7cdb-491c-a315-5bf8fa80c27b
< 3.2.7
CRITICAL 9.8 The Listingo theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via one of … wordfence
628bfa19-2ffa-426b-8b88-22a0c4d0ba92
< 3.2.3
CRITICAL 9.8 The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads du… wordfence
624c98c2-3fce-4f6b-a049-da3bce2a8c6a
< 2.2.24
CRITICAL 9.8 The SEUR Oficial plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.23. Th… wordfence
623acb6d-9cab-483c-ad51-88adff8847a4
< 8.1.6
CRITICAL 9.8 The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different v… wordfence
620e8931-64f0-4d9c-9a4c-1f5a703845ff
< 3.92.1
CRITICAL 9.8 The WordPress Automatic Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery and Arbitrary File Down… wordfence
6206a2f8-2de4-4c9f-b439-3c733a5a0a62 CRITICAL 9.8 The WP FoodBakery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3 via d… wordfence
6203ffaf-5efd-4c66-85f0-cc3a05a03084 CRITICAL 9.8 The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type val… wordfence
61e6db2f-5dfd-44ef-9500-9f0cb5cd67ba
< 1.29.3
CRITICAL 9.8 The WP Job Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.29.2 v… wordfence
618a9ad7-3a13-43e6-84f4-35287f07e1c0 CRITICAL 9.8 The CE21 Suite plugin for WordPress is vulnerable to sensitive information disclosure via the plugin-log.txt in versions… wordfence
61820ca5-5548-4155-b350-df3db1bc1661
< 5.6.68
CRITICAL 9.8 The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and inc… wordfence
6164c161-f764-4064-8139-609caad82204 CRITICAL 9.8 Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slidesh… wordfence
615d8b8f-037e-4741-bdb4-639daf690aff CRITICAL 9.8 The The Novel Design Store Directory plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… wordfence
613f4bd1-e29a-4853-84a2-3e1437f06d33
< 2.2.81
CRITICAL 9.8 The Events Made Easy plugin for WordPress is vulnerable to SQL Injection via the ‘lang’ parameter in versions up to,… wordfence
613f22f2-2f84-4d01-a1ea-c14a25843700
< 2.0.6
CRITICAL 9.8 Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPre… wordfence
613f2035-3061-429b-b218-83805287e4f3
< 3.28.21
CRITICAL 9.8 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress … wordfence
613e1862-e0b7-4012-a77d-b5fb56cbbb9c
< 1.2.2
CRITICAL 9.8 The 360 Product Rotation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… wordfence
6130d49f-61b7-4b70-b1a5-036346f82650 CRITICAL 9.8 The Baggage Freight Shipping Australia plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … wordfence
61080df6-836f-4365-964a-fa2517e8be5a
< 3.10.0
CRITICAL 9.8 The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and includ… wordfence
60f63cdc-9c19-4f6c-a555-519bdb61ce6d
< 1.6
CRITICAL 9.8 The RokMicroNews plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.5 due to… wordfence
60f043e9-7947-4fff-a9a8-94a1f421db7c
< 1.0.37
CRITICAL 9.8 The Woodmart Core plugin for WordPress is vulnerable to privilege escalation due to insufficient validation in its socia… wordfence
← Prev 61 62 63 64 65 66 67 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top