πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 7 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3ca6605f-7c9c-43c7-ae32-ca1d781c1e86
< 3.15
CRITICAL 9.9 The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal perm… wordfence
3b472eb8-9808-4a50-b2b4-0b0b3256053f
< 7.4.2
CRITICAL 9.9 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSort… wordfence
3b4012dd-7c0a-45f1-8ada-8f9dc6867e1e
< 1.2.2
CRITICAL 9.9 The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up … wordfence
38a405f2-344c-4ee1-a67e-5f6afad66b84 CRITICAL 9.9 The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using… wordfence
381ea693-3e59-4ecb-a96b-4b58d47298c0
< 15.5.9
CRITICAL 9.9 The Calendarista plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 15.5.7 due to… wordfence
37b9ed0e-5af2-47c1-b2da-8d103e4c31bf
< 4.3.1
CRITICAL 9.9 The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the… wordfence
2f0c85f4-07ae-4a2b-bd82-93467e7d9325
< 2.6.5
CRITICAL 9.9 The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
2d3150b3-fba1-4e89-8f4e-b6c605227395
< 21.3.2.1
CRITICAL 9.9 The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordP… wordfence
2ae916a0-b0a8-4722-9d8a-3d1f163bc8e5
< 10.1.76
CRITICAL 9.9 The WP Cost Estimation & Payment Forms Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, an… wordfence
29a2cb14-bf70-4936-a7c9-bf417a403de8
< 7.3.8
CRITICAL 9.9 The Zotpress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.3.7 due to insuffic… wordfence
2923afdd-36b7-4181-aade-d757a70a06c0
< 6.2.10
CRITICAL 9.9 The Advanced Custom Fields Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including… wordfence
2912f693-c8fd-48f7-8030-5e1f0edd715f
< 1.1.9
CRITICAL 9.9 The Contact Form to Any API plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.… wordfence
28ecf168-c215-4fc3-8dd7-1ab84ae6b4a6
< 3.0.9
CRITICAL 9.9 The Newspack Blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
28e4cc53-53c3-47bf-8ea4-818040d10abd
< 6.9.8
CRITICAL 9.9 The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.9.7 due t… wordfence
26e35c4a-79ec-4742-8004-1c799d2c56ff
< 2.12.3
CRITICAL 9.9 The Registrations for the Events Calendar – Event Registration Plugin plugin for WordPress is vulnerable to SQL Inject… wordfence
241dc2e4-b079-407b-b610-c40b23d038cb
< 4.6.0.4
CRITICAL 9.9 In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (wi… wordfence
1ffbff82-85ba-4f6f-b2de-9ba99003d981
< 1.3.1
CRITICAL 9.9 The Consulting Elementor Widgets plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1… wordfence
198ad1bf-7ce1-4367-bef7-1f58113c0719
< 8.1.8
CRITICAL 9.9 The Media Library Folders plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.1.7 du… wordfence
134ad095-b0a0-4f0f-832d-3e558d4a250a
< 2.5.1
CRITICAL 9.9 The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Exe… wordfence
107c82fa-fcb1-40df-9c53-bc8f23810f2a
< 1.6.5
CRITICAL 9.9 The BA Book Everything plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.4 due t… wordfence
0b748dc9-4d44-41dd-b159-380214e7646a
< 1.5
CRITICAL 9.9 Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress al… wordfence
0aced5de-e9df-4ffe-9d10-93dc3897ef4c
< 5.5.4
CRITICAL 9.9 The Element Pack Elementor Addons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … wordfence
0358d8f8-f7fd-487e-b75c-08e1cfdeeeec CRITICAL 9.9 The Unite Gallery Lite plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.62 due … wordfence
ffff2ff3-769d-4eb2-acbe-d8ce6f042581 CRITICAL 9.8 The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file typ… wordfence
ffeb4b5e-4c83-4b0e-a513-6b5cada95073
< 3.0.0
CRITICAL 9.8 The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4… wordfence
← Prev 4 5 6 7 8 9 10 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top