🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 69 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
562d0052-7f1a-441b-9ff7-1c8bcb4b74b4
< 5.8.3
CRITICAL 9.8 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ‘billing_f… wordfence
560b175b-ce2a-4161-aa6b-cd11d1377314 CRITICAL 9.8 The Satoshi theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the uplo… wordfence
55fd9199-66ab-4a43-ba2e-bea1467bf744 CRITICAL 9.8 The Drop Uploader for CF7 - Drag&Drop File Uploader Addon plugin for WordPress is vulnerable to arbitrary file uploads d… wordfence
55f507c4-8589-4fdb-92c2-935d38054817
< 1.0.6
CRITICAL 9.8 The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php. wordfence
55e0f0df-7be2-4e18-988c-2cc558768eff
< 5.9.9
CRITICAL 9.8 The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to,… wordfence
55abf798-f336-4262-9f52-4526a4bae15a CRITICAL 9.8 The Genesis Simple Love plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… wordfence
55a0b4ad-de5e-4203-a702-d498bf566165
< 1.2.8
CRITICAL 9.8 SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary… wordfence
5566a55e-81bb-4e14-98e1-1a548541e243
< 1.5.6
CRITICAL 9.8 The Form Block plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the f… wordfence
554a314c-9e8e-4691-9792-d086790ef40f
< 4.24.12
CRITICAL 9.8 The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.2… wordfence
552ec9fc-5bff-4bee-be04-39892c89cd59
< 1.2.0
CRITICAL 9.8 The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the … wordfence
54f1ebfb-67f1-461d-91f1-269b0a2c0653
< 1.0.3
CRITICAL 9.8 The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and … wordfence
54c1eb7b-c3fe-4975-9f51-df3aba53fe46
< 2.4.5
CRITICAL 9.8 The VR Calendar plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.4.4. … wordfence
54b079b5-35e4-4d65-97ce-6d0d2053886d
< 1.0.24
CRITICAL 9.8 The Agency Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.… wordfence
54901d01-241a-4027-ba72-2b983608f9c6
< 4.5.2
CRITICAL 9.8 The Advanced Post Manager for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.5.1 … wordfence
54553005-1869-4334-92ec-e37e8935d769
< 2.1
CRITICAL 9.8 SQL injection vulnerability in Apptha WordPress Video Gallery 2.0, 1.6, and earlier for WordPress allows remote attacker… wordfence
544b09a2-dfd4-4dee-8687-fe86cdc65f30
< 1.4.6
CRITICAL 9.8 The Material Dashboard plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions u… wordfence
541551d8-5510-43ff-b685-783d0d94c4bb CRITICAL 9.8 The moveto plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in an unknow… wordfence
5413ae2a-9afa-4ff6-b241-73b446881185 CRITICAL 9.8 The MyPixs plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.3 via the 'dow… wordfence
540d444f-7a6c-4c14-a9c7-52209ad59a11
< 1.5.1
CRITICAL 9.8 The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key which makes it possible for an u… wordfence
540ac650-6bfd-4ee2-b3c8-b6444a209b6a
< 2.0.9
CRITICAL 9.8 Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote … wordfence
54041d74-6d2e-4a70-aa35-46619afb9d8c CRITICAL 9.8 The hockeydata LOS plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.4. T… wordfence
53eba5b4-7cc0-48e1-bb9c-6ed3207151ab
< 6.6.1
CRITICAL 9.8 The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… wordfence
53e83037-2cc5-4dc9-b55d-03829df12a65
< 2.8.8
CRITICAL 9.8 The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc… wordfence
53cc91fa-51fd-4d16-b740-a48f8d446b5d
< 2.8.5
CRITICAL 9.8 The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable … wordfence
53b5a052-6e84-4eb5-a7f4-4e32f757f4d6
< 3.0.0
CRITICAL 9.8 The Smush – Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to Cross-Site Scripting le… wordfence
← Prev 66 67 68 69 70 71 72 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top