πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 68 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
58f8bba4-1be5-4111-aa41-d076a6f06948
< 1.6.4
CRITICAL 9.8 The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_fa… wordfence
58ea0c9c-f63d-4c31-b02e-a86d5fe732aa CRITICAL 9.8 The Flash News Theme for WordPress is vulnerable to Cross-Site Scripting in all versions due to inclusion of a vulnerabl… wordfence
58bd4a75-8e24-4810-8b9d-c9ffad1c2208
< 1.5
CRITICAL 9.8 The WP Donate plugin for WordPress is vulnerable to SQL Injection in donate-display.php in versions up to, and including… wordfence
589fa6f2-fa60-4bdc-9692-50d5591ceb93 CRITICAL 9.8 The FlipBook plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /fl… wordfence
588ece40-a848-4b2c-9db5-e63e0d11dda0
< 2.0.2
CRITICAL 9.8 The WP e-Commerce – Store Toolkit plugin for WordPress is vulnerable to authorization bypass due to a missing capabili… wordfence
5881d16c-84e8-4610-8233-cfa5a94fe3f9
< 3.9.2
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This… wordfence
5875a4c2-a309-41fb-8845-2935511ec6c0
< 2.1.6
CRITICAL 9.8 The UnGallery plugin for WordPress is vulnerable to Command Injection in versions before 2.1.6 via the 'search' paramete… wordfence
586250e9-bc35-4c9d-b558-7346efd4dce9
< 2.9.23.1
CRITICAL 9.8 The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation … wordfence
5846b5d9-5b69-47b0-b787-6a3416a5076e
< 1.3.2
CRITICAL 9.8 The WpBookingly plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.1 via d… wordfence
580f5cd1-2cda-4e8e-81b5-36ce39ebd907 CRITICAL 9.8 The Zarzadzanie Kontem plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
5804da94-1dee-47f8-930b-c5413d5506b9
< 1.16
CRITICAL 9.8 The Direct Download for Woocommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in… wordfence
57e37b16-230c-4cb5-96f7-4d5c20535e06
< 14.8.1
CRITICAL 9.8 The Simple Link Directory Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to 14.8.1 (… wordfence
57be90d8-dab7-49c8-bcdf-32e967ee1716
< 2.6.5
CRITICAL 9.8 The bbPress plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to, and including,… wordfence
57b97d58-28b6-4d50-81b5-a35c0b8cb180
< 2.5.3
CRITICAL 9.8 The HTML5 Radio Player - WPBakery Page Builder Addon plugin for WordPress is vulnerable to arbitrary file uploads due to… wordfence
57a81776-643d-4057-9d81-b79ad396cced
< 1.18
CRITICAL 9.8 The RokNewsPager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… wordfence
57704203-ed74-4100-900c-3f35c726e51e CRITICAL 9.8 Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/up… wordfence
575d1353-70af-4200-9088-662f7a052b76
< 4.9.800
CRITICAL 9.8 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing… wordfence
5754ffd6-81bb-491b-9272-627e8c52a22c
< 1.1.9
CRITICAL 9.8 The "AllWebMenus WordPress Menu Plugin" plugin for WordPress is vulnerable to arbitrary file uploads due to missing file… wordfence
57531d89-1f54-43f4-a19d-9fda5e69f2ad
< 3.1.4
CRITICAL 9.8 A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress Wo… wordfence
57450aba-ba77-46f2-95b8-b886f4cc14fe CRITICAL 9.8 The Plugin Name: Sovratec Case Management plugin for WordPress is vulnerable to arbitrary file uploads in all versions … wordfence
570f680b-b688-49ad-9eed-0bc966a4cdf7 CRITICAL 9.8 The Faction theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.1.1. This is d… wordfence
56f13af3-71b6-42d4-9fda-a75778f32091
< 3.4.31
CRITICAL 9.8 The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in… wordfence
5683f121-a670-4b16-ac0f-c2cc569c05d4 CRITICAL 9.8 The Javo Core plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.0.0.26… wordfence
56758c67-5df2-4e28-8095-a73151f9cb8c
< 1.2.11
CRITICAL 9.8 The Hara theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.10. This makes … wordfence
56465338-f9be-49c5-8125-c6729287d590
< 1.7.7
CRITICAL 9.8 The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and Java… wordfence
← Prev 65 66 67 68 69 70 71 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top