🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 68 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6164c161-f764-4064-8139-609caad82204 CRITICAL 9.8 Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slidesh… — wordfence
615d8b8f-037e-4741-bdb4-639daf690aff CRITICAL 9.8 The The Novel Design Store Directory plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… — wordfence
613f4bd1-e29a-4853-84a2-3e1437f06d33
< 2.2.81
CRITICAL 9.8 The Events Made Easy plugin for WordPress is vulnerable to SQL Injection via the ‘lang’ parameter in versions up to,… — wordfence
613f22f2-2f84-4d01-a1ea-c14a25843700
< 2.0.6
CRITICAL 9.8 Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPre… — wordfence
613f2035-3061-429b-b218-83805287e4f3
< 3.28.21
CRITICAL 9.8 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress … — wordfence
613e1862-e0b7-4012-a77d-b5fb56cbbb9c
< 1.2.2
CRITICAL 9.8 The 360 Product Rotation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… — wordfence
6130d49f-61b7-4b70-b1a5-036346f82650 CRITICAL 9.8 The Baggage Freight Shipping Australia plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … — wordfence
61080df6-836f-4365-964a-fa2517e8be5a
< 3.10.0
CRITICAL 9.8 The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and includ… — wordfence
60f63cdc-9c19-4f6c-a555-519bdb61ce6d
< 1.6
CRITICAL 9.8 The RokMicroNews plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.5 due to… — wordfence
60f043e9-7947-4fff-a9a8-94a1f421db7c
< 1.0.37
CRITICAL 9.8 The Woodmart Core plugin for WordPress is vulnerable to privilege escalation due to insufficient validation in its socia… — wordfence
60dacb8d-0de6-4755-8857-6b05083a23b8
< 1.4.3
CRITICAL 9.8 The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions u… — wordfence
60a7cce0-637f-49bd-aa4a-fd7023d99a64
< 1.6.3
CRITICAL 9.8 The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover i… — wordfence
608b0506-074b-4df3-8c30-57cfb090f553
< 2.3.0
CRITICAL 9.8 The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its o… — wordfence
607c20b1-f8da-4f3f-a070-abdae64c8fc8
< 1.1.97
CRITICAL 9.8 The Image Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'image-slider-widget/trunk/inc/func… — wordfence
6065ad75-1685-4f1d-9ba9-d4c8ec840521
< 2022.6
CRITICAL 9.8 The Stop Spammers Security plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … — wordfence
60656eff-7851-4b6e-97f4-840c299b1e4e
< 3.8.0
CRITICAL 9.8 The WavePlayer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '… — wordfence
60470d54-2105-4dc1-8e0c-670e8e22977a CRITICAL 9.8 The DigiWidgets Image Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and incl… — wordfence
604249c6-b23a-40e9-984d-2014f5c97249
< 0.8.0
CRITICAL 9.8 The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and… — wordfence
60405e54-e869-4623-892c-0821014f887b
< 1.2
CRITICAL 9.8 The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including… — wordfence
6031edec-4274-4e42-9e3a-ce0c94958b17
< 9.2.6
CRITICAL 9.8 The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame… — wordfence
602e088e-57af-4b30-96c3-a44b2a8e4edb CRITICAL 9.8 The Advanced Advertising System plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… — wordfence
60242725-200e-4794-acdc-2ab4a1e8e4fc CRITICAL 9.8 SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows r… — wordfence
601e52b6-36eb-4739-9b04-db779befa899 CRITICAL 9.8 The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in… — wordfence
601d70ff-2e0e-403b-9c58-130d378a8240
< 1.7.1
CRITICAL 9.8 The WooCommerce Ninja Forms Product Add-ons plugin for WordPress is vulnerable to arbitrary file uploads due to missing … — wordfence
600f38eb-3c13-4792-8079-944ea0238ad2 CRITICAL 9.8 The Contact Page With Google Map plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file … — wordfence
← Prev 65 66 67 68 69 70 71 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top