🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 64 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6b558818-f459-4bc1-893c-8c1c7bf9d6d2
< 3.7.22
CRITICAL 9.8 Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus di… — wordfence
6b5288db-8996-4363-bdc0-d3bdd2445e9f CRITICAL 9.8 The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Remote Code Exec… — wordfence
6b48cae6-254c-4882-a464-3a44a63cadf5
< 3.16.12
CRITICAL 9.8 The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter… — wordfence
6b456815-ffdf-41fb-b4a8-0f22fd059d34 CRITICAL 9.8 The AJAX Store Locator plugin for WordPress is vulnerable to SQL Injection via the ‘StoreLocation’ parameter in vers… — wordfence
6b443610-416c-41d6-9449-9e20f719af06 CRITICAL 9.8 The Contus Video Gallery plugin for WordPress is vulnerable to Arbitrary File Upload due to missing file type validation… — wordfence
6b431493-fd96-495b-aaa7-6dfeef04b011
< 3.7.1
CRITICAL 9.8 The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement v… — wordfence
6b26f41e-fab8-4fe4-b5ab-4c238a433eab CRITICAL 9.8 The User registration & user profile – UserPlus plugin for WordPress is vulnerable to privilege escalation in all vers… — wordfence
6b15eca5-fd47-4f8f-8ade-3a90e0bfc110
< 7.3.2
CRITICAL 9.8 The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, a… — wordfence
6afbdac4-e52a-4ad3-a99a-2d75e698e0fc
< 2.9.3
CRITICAL 9.8 The JS Help Desk plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.9.2. Thi… — wordfence
6aef6fbb-be8c-49e1-ada5-7b4aa8b2ff72
< 1.3.2
CRITICAL 9.8 The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication B… — wordfence
6aeb0352-66ab-45d4-ad61-f425d7d41f45 CRITICAL 9.8 The Daily Edition theme for WordPress is vulnerable to SQL Injection via the ‘&id’ parameter in versions up to, and … — wordfence
6abbdecd-782a-44a2-981a-ae6caa50dd6a CRITICAL 9.8 The Article analytics plugin for WordPress is vulnerable to SQL Injection via the 'p' parameter in all versions up to, a… — wordfence
6ab975b0-4216-46df-bf5e-91e403728e5b
< 1.5.4
CRITICAL 9.8 The wpDataTables plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… — wordfence
6ab578cd-3a0b-43d3-aaa7-0a01f431a4e2
< 4.2.5.8
CRITICAL 9.8 The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all ve… — wordfence
6ab0d342-bfa7-4760-b839-37c3354414ca CRITICAL 9.8 The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5… — wordfence
6a7e794b-aa0e-4db3-8999-c9c5134a4ded CRITICAL 9.8 The eTemplates plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.2.1 due to insuff… — wordfence
6a60e2c3-4597-4b21-ad20-6a00e483fcf1
< 16.6
CRITICAL 9.8 The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… — wordfence
6a4d5a40-2ec0-468e-bafb-a713629f6006
< 4.51
CRITICAL 9.8 The Webcam Video Conference plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… — wordfence
6a0be61b-a1ee-499f-b991-58d5494bce18
< 1.0.1
CRITICAL 9.8 The Zendrop – Global Dropshipping plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and … — wordfence
6a050764-0ba6-49a4-bd71-f79e3129fc4c
< 2.9.9
CRITICAL 9.8 The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to mis… — wordfence
6a04e6ad-9365-4cb5-a0a0-82e047647d6b
< 4.2.9
CRITICAL 9.8 The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modi… — wordfence
69b2f126-8f57-4bea-b0e9-14b4566ac470
< 2.0.3
CRITICAL 9.8 The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection via the 'orderby' and 'order' parameters. — wordfence
6989e54b-ce5e-4c79-bd0d-0f7978a4bd44
< 4.6.1
CRITICAL 9.8 The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?pag… — wordfence
6980248b-195d-4e03-853e-a767a9a4b513 CRITICAL 9.8 The Partners plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.2.0 via dese… — wordfence
6980112b-a555-47a4-b2d7-f0187d52fc63
< 1.2.4
CRITICAL 9.8 The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to … — wordfence
← Prev 61 62 63 64 65 66 67 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top