🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 65 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6969d281-f280-4714-9859-38ac66e9cc60
< 3.0.6
CRITICAL 9.8 The Edwiser Bridge plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5. … — wordfence
695819e6-2574-4047-a55d-a78289c29ba0
< 1.5.55
CRITICAL 9.8 Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL inje… — wordfence
694b67d2-7d60-4764-a2c0-02698c331772
< 3.8.1
CRITICAL 9.8 The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 vi… — wordfence
692a5838-4a32-4444-b1a0-018fa25594a9
< 2.0.2
CRITICAL 9.8 The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… — wordfence
68ed894d-b48b-42ef-89a9-b6a2ea093fc4
< 1.4
CRITICAL 9.8 The Custom Fields Account Registration For Woocommerce plugin for WordPress is vulnerable to Privilege Escalation in all… — wordfence
68e838d4-2ff2-4925-b2ff-ba3f7b379010
< 3.1.4
CRITICAL 9.8 A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress Word… — wordfence
68e0f54d-08ec-4e41-ac9b-d72cdde5a724 CRITICAL 9.8 The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the… — wordfence
68dd9f6f-ccee-4a27-bd21-2fb32b92cc62
< 6.0.7.2
CRITICAL 9.8 The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6… — wordfence
68ae048c-a897-4061-b839-56ca0dbb2581
< 3.0
CRITICAL 9.8 The kineticPay for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… — wordfence
689e86c4-5330-4837-b3ff-2553fa1c2ead
< 3.1.1
CRITICAL 9.8 The Global DNS plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.0. … — wordfence
6843939b-889f-45d7-9758-4b76a20d15f1 CRITICAL 9.8 The Dynamic Font Replacement DFR4WP EN plugin for WordPress is vulnerable to arbitrary file deletion in versions up to ,… — wordfence
6837b91d-b3ba-435a-965b-fa18d9b9b9c8
< 9.2.7
CRITICAL 9.8 The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame… — wordfence
68052614-204f-4237-af0e-4b8210ebd59f
< 5.15.2
CRITICAL 9.8 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, a… — wordfence
67df10cc-ce3c-4157-9860-7e367062f710 CRITICAL 9.8 The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remo… — wordfence
67d8dc60-e66e-4f2f-a06d-f95375ca1994 CRITICAL 9.8 The WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. plugin for WordPress is vulnerable to arbitrar… — wordfence
67c7e67e-3e68-4f49-9d81-fa0ed451376e
< 1.7.0
CRITICAL 9.8 The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more … — wordfence
67c4066f-b8bc-4cd0-ae47-844af23e003f CRITICAL 9.8 The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including… — wordfence
67b152b5-e662-4dbd-a7db-87fc63cfb307
< 2.1.1
CRITICAL 9.8 TheTop Quark Architecture plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… — wordfence
67890f13-df93-4c1d-aabe-a90437183bbd
< 2.20.1
CRITICAL 9.8 The Masteriyo LMS PRO plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2… — wordfence
677a9713-e7c6-477d-9ba9-8b0e2bdb2c6d CRITICAL 9.8 The Teddy Bear Customize Addon plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inc… — wordfence
672edfd2-ca4b-4937-8237-3c0a4acc8690 CRITICAL 9.8 The pb-embedFlash plugin for WordPress is vulnerable to Remote File Inclusion with media files in versions up to, and in… — wordfence
6711f542-8b75-4968-86ac-9686ded775b7
< 2.1.2
CRITICAL 9.8 Version 2.1.1 of WordPress was injected with malicious code that supplied attackers with backdoor access to WordPress si… — wordfence
66ce2d12-8f57-4140-b3cf-0fc8c1c4f3d5
< 1.1.8
CRITICAL 9.8 SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar pl… — wordfence
66c20a71-96e2-4d5e-a2ed-7e7afbe85306 CRITICAL 9.8 The Automatic Translation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… — wordfence
66a6569b-88ec-42d8-8396-6e62f1c51b24 CRITICAL 9.8 The Invit0r plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the ofc… — wordfence
← Prev 62 63 64 65 66 67 68 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top