πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 67 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5bf6d60f-57ac-4cbc-895f-a7db548cbf67
< 1.2.0
CRITICAL 9.8 The Api2Cart Bridge Connector plugin for WordPress is vulnerable to arbitrary file uploads due to missing or incorrect f… wordfence
5bde312b-abbb-4e8e-91c6-a42dadbaedb5
< 14.4.5
CRITICAL 9.8 The StoreKeeper for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… wordfence
5b7c8a73-92da-4d2f-a37c-2ac380e56c5f CRITICAL 9.8 The Energia - Renewable Energy WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to missin… wordfence
5b75c322-539d-44e9-8f26-5ff929874b67
< 1.2.6
CRITICAL 9.8 The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.… wordfence
5b67a9ce-44ad-4438-a545-84ca69e2ef47
< 1.0.7
CRITICAL 9.8 The Fable Extra plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.6. This… wordfence
5b5ae0ae-1272-4bac-867f-4ff84155799e
< 1.0.8
CRITICAL 9.8 The HAPPY – Helpdesk Support Ticket System plugin for WordPress is vulnerable to Remote Code Execution in all versions… wordfence
5b546d24-82c1-4598-8926-6e73a4784b38
< 4.6.6
CRITICAL 9.8 The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation… wordfence
5b53fa6f-7fb8-4643-a365-7630102e7e46
< 1.4.7
CRITICAL 9.8 The BigContact Contact Page plugin for WordPress is vulnerable to SQL Injection via several parameters in versions befor… wordfence
5b39be2a-0769-4f3e-885f-a534682670ad CRITICAL 9.8 The WPCHURCH plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7.0. This ma… wordfence
5b07ea6a-511d-44ab-b0b7-5124702ad47d
< 3.9.1
CRITICAL 9.8 The Login as User or Customer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and inc… wordfence
5b00cf9b-60c3-44a4-98a7-ee0f3e763c87
< 3.4.11
CRITICAL 9.8 The Sunshine Photo Cart plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.4… wordfence
5ad12146-200b-48e5-82de-7572541edcc4
< 4.9.1
CRITICAL 9.8 The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and includin… wordfence
5ab2c74d-b83b-40ea-951c-83aeb76a7515 CRITICAL 9.8 The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass… wordfence
5a97877b-fb4d-4e87-bcff-56be65fee6ce
< 20190426
CRITICAL 9.8 The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… wordfence
5a7f869d-e915-4048-b0e1-36cf25e732f9 CRITICAL 9.8 The Audio Record plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… wordfence
5a5f31ad-75f9-4534-a8a6-e76f9aefbd80 CRITICAL 9.8 The Hospital Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing… wordfence
5a5d5dbd-36f0-4886-adf8-045ec9c2e306
< 3.6
CRITICAL 9.8 The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
59be1fc7-2854-404d-8e9d-dd9bd26e6a2c
< 3.11
CRITICAL 9.8 The Rencontre – Dating Site plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and in… wordfence
59aebe74-cf53-49f4-8f20-ebb5503d7dbd
< 5.9.9.7
CRITICAL 9.8 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via… wordfence
59a645e4-2a23-4440-a463-fa197dfa20b2 CRITICAL 9.8 The WA Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the β€˜wa_forms_Id’ parameter in v… wordfence
59a05868-7457-4fb1-845e-bf7044d5cb81
< 2.2.2
CRITICAL 9.8 The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader… wordfence
599c6984-5d52-4d0f-86a1-b88f6c9797ed
< 2.2.8
CRITICAL 9.8 The Buddyforms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.2.7 due to insuff… wordfence
598fffcd-0318-4e41-8837-f65761390c19
< 3.1.5
CRITICAL 9.8 The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers. wordfence
595fac73-c583-4712-ad37-fbd0fa3eb147
< 1.3.6
CRITICAL 9.8 SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header. wordfence
5933fc11-8f06-4d58-9483-d06997e5d731
< 0.3.0.04
CRITICAL 9.8 The Filebase Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includi… wordfence
← Prev 64 65 66 67 68 69 70 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top