πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 66 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
66969472-4b3c-4d56-b761-523ea854e3db
< 1.5.8
CRITICAL 9.8 The Leaflet Maps Marker Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… — wordfence
668ba3a9-d53c-45ab-854f-1a9e83dd54b8
< 1.6.7
CRITICAL 9.8 The WP e-Commerce – Store Exporter plugin for WordPress is vulnerable to authorization bypass due to a missing capabil… — wordfence
6687ebbe-fdf4-4ecb-bf59-034bb4b0104c
< 3.5.1
CRITICAL 9.8 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege… — wordfence
66845165-02c7-4f4a-93fd-1a309fb7b386 CRITICAL 9.8 The CAFEHAUS API plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, … — wordfence
66749606-e76f-41fb-bcf1-c06681de2ee3 CRITICAL 9.8 The Master Slider Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3… — wordfence
664e6e2a-faa1-4609-b250-d7e94c5d5a04
< 1.6.3
CRITICAL 9.8 The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… — wordfence
6629e1a9-3b28-4c8c-95d4-3c0011a7364a
< 2.1.5
CRITICAL 9.8 An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_no… — wordfence
661d4ea9-572d-4544-b5cf-39fd69c104a6
< 3.9.8
CRITICAL 9.8 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… — wordfence
65fc2929-b65b-451b-b90d-6739a673ac16 CRITICAL 9.8 The MBStore - Digital WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions … — wordfence
65ebc744-6cc2-47ce-b225-81820e49d59c
< 1.6.0
CRITICAL 9.8 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versio… — wordfence
65e2e9e3-2778-4baf-8269-fc13d5ef1212
< 2.7.2
CRITICAL 9.8 The JS Help Desk plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.7.1. T… — wordfence
65c3ca36-79e6-47f8-9524-27e7631f4caf
< 3.21.1
CRITICAL 9.8 The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Cod… — wordfence
65be9417-7029-4f34-b834-98208a42743b
< 8.0.0
CRITICAL 9.8 The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to… — wordfence
65988550-d39d-40be-8d25-647e7237062d
< 6.1.1
CRITICAL 9.8 The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all ver… — wordfence
657f3bd7-2cdc-4eb6-ba50-7c7fca468df0
< 5.0.13
CRITICAL 9.8 The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and… — wordfence
65386d2b-5d0c-4e49-a79a-a793b4b599e0 CRITICAL 9.8 The FW Food Menu – Responsive food menu with ordering & delivery solutions plugin for WordPress is vulnerable to arbit… — wordfence
651aa149-0968-4916-b260-067d32193d83 CRITICAL 9.8 The DoLeads Integrator plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.2… — wordfence
65192fdb-86db-475a-8c61-4db922920cfe
< 250214
CRITICAL 9.8 The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216… — wordfence
65166432-a877-4070-94c1-cdaf7e5d7586
< 1.5.99
CRITICAL 9.8 The Booking Package plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including 1.5.98 d… — wordfence
64eb4bfe-09b4-43c7-9d7e-f14fc5edf3c1
< 6.90
CRITICAL 9.8 The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in … — wordfence
64e806df-4919-4a58-8f21-075f09668174
< 1.0.73
CRITICAL 9.8 The 10Web Map Builder for Google Maps plugin for WordPress is vulnerable to generic SQL Injection via the multiple param… — wordfence
64e125c7-3f1e-43ed-8655-e0fbb95bc84b CRITICAL 9.8 The "CStar Design WordPress Theme" theme for WordPress is vulnerable to SQL Injection via the β€˜id’ parameter in vers… — wordfence
6494e54c-db04-41f9-8b91-6ad12528cf01
< 3.1.17
CRITICAL 9.8 The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… — wordfence
647cc71d-4d3a-4722-b498-baaee2450809
< 10.6.7
CRITICAL 9.8 The RSVPMaker plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 10.6.6 via de… — wordfence
647a2f27-092a-4db1-932d-87ae8c2efcca CRITICAL 9.8 The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via… — wordfence
← Prev 63 64 65 66 67 68 69 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top