🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 66 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5e2bf4a8-1dca-47fb-8164-acca0b2cf4f2
< 2.0.3.2
CRITICAL 9.8 The Wholesale Lead Capture Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to mi… wordfence
5e29b10e-81d5-4247-bfe8-2400bcd9aef9
< 3.1.6
CRITICAL 9.8 LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection. wordfence
5e24feac-1812-45d7-b3c3-27787eed1cf1 CRITICAL 9.8 The CE21 Suite plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability che… wordfence
5e15e36e-55f9-4095-a0ba-48ef9434606a
< 2.2.6
CRITICAL 9.8 The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass… wordfence
5e0ce0dc-34eb-4577-82a5-8ed822847ff4
< 1.4.6.1
CRITICAL 9.8 The WPS Limit Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.6.… wordfence
5e0bcf70-2ffc-45c8-b63e-a8376b6cd22b
< 2.33
CRITICAL 9.8 The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via de… wordfence
5dfc2249-3761-49c6-966e-73c33be74c0e
< 5.9.0
CRITICAL 9.8 The PGS Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.8.0 via … wordfence
5dfa4ddf-bbe7-49b1-8b0d-c030ae81d0e8
< 0.4
CRITICAL 9.8 The Visitors Online by BestWebSoft plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and in… wordfence
5de56a2e-f8e2-47d9-8a2b-989de640f018
< 1.4.4
CRITICAL 9.8 SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote… wordfence
5dc8feae-fc89-4152-b9b2-2b70e6ccb30b CRITICAL 9.8 The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
5dc72d78-d47c-4b36-8d69-8672e15ddf8c
< 3.15.3
CRITICAL 9.8 The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP F… wordfence
5d875004-a589-4657-953c-ca175e3157c2
< 2.8.4
CRITICAL 9.8 The Travel Booking WordPress Theme for WordPress is vulnerable to blind SQL Injection via the ‘location_id’ paramete… wordfence
5d84d749-0ab5-49dd-8e4f-45681f197742
< 3.12.8
CRITICAL 9.8 The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to … wordfence
5d7b75a4-67b4-4347-91a6-dbf98da5ceaf CRITICAL 9.8 The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Res… wordfence
5d5c553f-247d-4feb-8027-822cfaca4adf
< 2.4
CRITICAL 9.8 The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to mis… wordfence
5d371a8e-2997-4be3-afd9-60f752a6721c
< 5.2.7
CRITICAL 9.8 The OMGF Pro plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 5… wordfence
5d07d5e9-be7c-4c16-b931-d909ed8be361
< 1.11.4
CRITICAL 9.8 The Login with WHMCS plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 1.11.3… wordfence
5ce4b3cf-1c36-4596-b113-055945fceeb6
< 1.6.10
CRITICAL 9.8 The Pix 4x sem juros - Pagaleve plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… wordfence
5ca1c55a-cd4e-429a-ab74-dd1bad1a65f5
< 3.1.5
CRITICAL 9.8 The SupportCandy plugin for WordPress is vulnerable to SQL injection via the 'parse_user_filters' function in versions u… wordfence
5c9a23a3-5eb5-4f5b-bf32-c9d163426f29
< 5.0.12
CRITICAL 9.8 The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, … wordfence
5c9320f9-2e1a-4d76-850b-fa6fb68cd09f CRITICAL 9.8 The Realty Workstation plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including,… wordfence
5c79d861-e2e8-4fca-883f-79401544b0b1 CRITICAL 9.8 The RLSWordPressSearch plugin for WordPress is vulnerable to generic SQL Injection via the 'agentid' parameter in the 'r… wordfence
5c75c156-225c-465a-8d03-35a6669e9c04
< 1.0.12
CRITICAL 9.8 The Calculated Fields Form plugin for WordPress is vulnerable to SQL Injection via Cross-Site Request Forgery in version… wordfence
5c42a966-0035-4c12-8aa1-226a0157d98f
< 3.8.9.1
CRITICAL 9.8 The WP eCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ‘view_purchlogs_by_status’ para… wordfence
5c024c77-31a8-45b8-9fcb-7ba729bec32c CRITICAL 9.8 The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter. wordfence
← Prev 63 64 65 66 67 68 69 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top