🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 69 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5fdd2919-396b-41ff-ae92-1b6fee5c6f5e
< 2.4.1
CRITICAL 9.8 The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any a… — wordfence
5fa37909-932c-4879-bbf0-8b44cc995cc0
< 1.7.0
CRITICAL 9.8 The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8… — wordfence
5f98f4b3-8cce-45dd-a138-5f2c8031fab5
< 2.9.2
CRITICAL 9.8 The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allo… — wordfence
5f4d613d-f040-4b92-8192-483e66fac5fd
< 1.3.6
CRITICAL 9.8 The Oxpitan theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.5. This make… — wordfence
5f3b0e75-d2f0-48b7-ba33-75c4e998030e
< 6.3-revision-1
CRITICAL 9.8 The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all vers… — wordfence
5f1700c2-9c1f-4882-9f11-13b4ee8477a9 CRITICAL 9.8 The WP Shop plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on it's ajax fu… — wordfence
5ea26b4c-598b-486e-a19b-0bb83774239d
< 2.8
CRITICAL 9.8 The Happy Coders OTP Login for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up… — wordfence
5e9d5c93-dcd7-450e-8c52-5c95fc5473d2 CRITICAL 9.8 The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the db… — wordfence
5e999e0f-463c-4676-ad18-f4b467bc4bfc
< 4.1.8
CRITICAL 9.8 A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. … — wordfence
5e90704e-1a0c-448c-9139-542927cfa4f8
< 1.2.3
CRITICAL 9.8 PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordP… — wordfence
5e491592-a17f-4789-8faa-d2a60b8ced70
< 2.7.5
CRITICAL 9.8 The Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.7.4… — wordfence
5e2bf4a8-1dca-47fb-8164-acca0b2cf4f2
< 2.0.3.2
CRITICAL 9.8 The Wholesale Lead Capture Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to mi… — wordfence
5e29b10e-81d5-4247-bfe8-2400bcd9aef9
< 3.1.6
CRITICAL 9.8 LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection. — wordfence
5e24feac-1812-45d7-b3c3-27787eed1cf1 CRITICAL 9.8 The CE21 Suite plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability che… — wordfence
5e15e36e-55f9-4095-a0ba-48ef9434606a
< 2.2.6
CRITICAL 9.8 The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass… — wordfence
5e0ce0dc-34eb-4577-82a5-8ed822847ff4
< 1.4.6.1
CRITICAL 9.8 The WPS Limit Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.6.… — wordfence
5e0bcf70-2ffc-45c8-b63e-a8376b6cd22b
< 2.33
CRITICAL 9.8 The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via de… — wordfence
5e0116d6-91c3-4212-9c68-6b706ab09768
< 1.8.6
CRITICAL 9.8 The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injecti… — wordfence
5dfc2249-3761-49c6-966e-73c33be74c0e
< 5.9.0
CRITICAL 9.8 The PGS Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.8.0 via … — wordfence
5dfa4ddf-bbe7-49b1-8b0d-c030ae81d0e8
< 0.4
CRITICAL 9.8 The Visitors Online by BestWebSoft plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and in… — wordfence
5de56a2e-f8e2-47d9-8a2b-989de640f018
< 1.4.4
CRITICAL 9.8 SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote… — wordfence
5dc8feae-fc89-4152-b9b2-2b70e6ccb30b
< 2.4.0
CRITICAL 9.8 The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … — wordfence
5dc72d78-d47c-4b36-8d69-8672e15ddf8c
< 3.15.3
CRITICAL 9.8 The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP F… — wordfence
5d875004-a589-4657-953c-ca175e3157c2
< 2.8.4
CRITICAL 9.8 The Travel Booking WordPress Theme for WordPress is vulnerable to blind SQL Injection via the ‘location_id’ paramete… — wordfence
5d84d749-0ab5-49dd-8e4f-45681f197742
< 3.12.8
CRITICAL 9.8 The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to … — wordfence
← Prev 66 67 68 69 70 71 72 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top