πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 65 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
60a7cce0-637f-49bd-aa4a-fd7023d99a64
< 1.6.3
CRITICAL 9.8 The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover i… wordfence
608b0506-074b-4df3-8c30-57cfb090f553
< 2.3.0
CRITICAL 9.8 The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its o… wordfence
607c20b1-f8da-4f3f-a070-abdae64c8fc8
< 1.1.97
CRITICAL 9.8 The Image Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'image-slider-widget/trunk/inc/func… wordfence
6065ad75-1685-4f1d-9ba9-d4c8ec840521
< 2022.6
CRITICAL 9.8 The Stop Spammers Security plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … wordfence
60656eff-7851-4b6e-97f4-840c299b1e4e
< 3.8.0
CRITICAL 9.8 The WavePlayer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '… wordfence
60470d54-2105-4dc1-8e0c-670e8e22977a CRITICAL 9.8 The DigiWidgets Image Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and incl… wordfence
604249c6-b23a-40e9-984d-2014f5c97249
< 0.8.0
CRITICAL 9.8 The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and… wordfence
60405e54-e869-4623-892c-0821014f887b
< 1.2
CRITICAL 9.8 The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including… wordfence
6031edec-4274-4e42-9e3a-ce0c94958b17
< 9.2.6
CRITICAL 9.8 The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame… wordfence
602e088e-57af-4b30-96c3-a44b2a8e4edb CRITICAL 9.8 The Advanced Advertising System plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… wordfence
60242725-200e-4794-acdc-2ab4a1e8e4fc CRITICAL 9.8 SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows r… wordfence
601e52b6-36eb-4739-9b04-db779befa899 CRITICAL 9.8 The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in… wordfence
601d70ff-2e0e-403b-9c58-130d378a8240
< 1.7.1
CRITICAL 9.8 The WooCommerce Ninja Forms Product Add-ons plugin for WordPress is vulnerable to arbitrary file uploads due to missing … wordfence
600f38eb-3c13-4792-8079-944ea0238ad2 CRITICAL 9.8 The Contact Page With Google Map plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file … wordfence
5fdd2919-396b-41ff-ae92-1b6fee5c6f5e
< 2.4.1
CRITICAL 9.8 The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any a… wordfence
5fa37909-932c-4879-bbf0-8b44cc995cc0
< 1.7.0
CRITICAL 9.8 The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8… wordfence
5f98f4b3-8cce-45dd-a138-5f2c8031fab5
< 2.9.2
CRITICAL 9.8 The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allo… wordfence
5f4d613d-f040-4b92-8192-483e66fac5fd
< 1.3.6
CRITICAL 9.8 The Oxpitan theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.5. This make… wordfence
5f3b0e75-d2f0-48b7-ba33-75c4e998030e
< 6.3-revision-1
CRITICAL 9.8 The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all vers… wordfence
5f1700c2-9c1f-4882-9f11-13b4ee8477a9 CRITICAL 9.8 The WP Shop plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on it's ajax fu… wordfence
5ea26b4c-598b-486e-a19b-0bb83774239d
< 2.8
CRITICAL 9.8 The Happy Coders OTP Login for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up… wordfence
5e9d5c93-dcd7-450e-8c52-5c95fc5473d2 CRITICAL 9.8 The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the db… wordfence
5e999e0f-463c-4676-ad18-f4b467bc4bfc
< 4.1.8
CRITICAL 9.8 A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. … wordfence
5e90704e-1a0c-448c-9139-542927cfa4f8
< 1.2.3
CRITICAL 9.8 PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordP… wordfence
5e491592-a17f-4789-8faa-d2a60b8ced70
< 2.7.5
CRITICAL 9.8 The Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.7.4… wordfence
← Prev 62 63 64 65 66 67 68 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top