πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,406
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,406 vulnerabilities found (page 70 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5391ad0a-a5c7-4fd8-b94e-9236cca41568 CRITICAL 9.8 The JS Job Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… wordfence
535f9f16-a7fc-40fe-8be1-90c542675cc4 CRITICAL 9.8 The Woolook plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.0. This mak… wordfence
53580b24-c0a7-4578-bb11-5952ebcacc42 CRITICAL 9.8 The UltimateWoo plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.1.10 via … wordfence
531e6da9-a24c-4b75-b909-ec4614075044 CRITICAL 9.8 The PIMP theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7 via deseria… wordfence
531d57c4-404a-475e-842a-08425959e150 CRITICAL 9.8 The vBSSO-lite plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an… wordfence
52db8d41-859a-4d68-8b83-3d3af8f1bf64
< 1.2.6
CRITICAL 9.8 The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on severa… wordfence
52d05693-469f-4fd9-800a-d8b9b94760fb CRITICAL 9.8 The WooCommerce Designer Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… wordfence
52c19707-df18-4239-af46-12ea5ee86a4b
< 4.03.33
CRITICAL 9.8 The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin … wordfence
529c5785-214e-41e7-8cf3-4ff3d256e27c CRITICAL 9.8 SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers t… wordfence
5284aef6-8fcd-4a75-a189-b2223bb83b60 CRITICAL 9.8 The CBX Poll plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.7 via dese… wordfence
525b466d-137a-467b-8b49-e51393a73866 CRITICAL 9.8 The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in ver… wordfence
523b5dd3-eb73-4156-ad2b-4d532e8d40f3
< 2.6.60
CRITICAL 9.8 The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to privilege escalation in all versi… wordfence
522ecc1c-5834-4325-9234-79cf712213f3
< 1.7.0.13
CRITICAL 9.8 The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu… wordfence
5228221f-b0b4-4faf-bde6-07666a96a278
< 3.6.3
CRITICAL 9.8 The Order Notification for WooCommerce – Get Audio Alert on new Orders plugin for WordPress is vulnerable to Remote Co… wordfence
521b1786-3527-4b4e-b1c4-ff4fbfed8107 CRITICAL 9.8 The My Reading Library plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0 … wordfence
52198053-206c-4002-8e26-dd5b4850e151
< 1.6.30
CRITICAL 9.8 The SalesKing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.15. This … wordfence
520c1e8b-d0c1-4201-90bf-0cefab9af7e0 CRITICAL 9.8 The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all ver… wordfence
5205fcde-2e6c-49de-b132-1ebefcd1ba59
< 1.4.4
CRITICAL 9.8 Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote att… wordfence
51fc7d47-2a0f-4713-9859-120321aa32dc
< 3.3.7
CRITICAL 9.8 The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account take… wordfence
51f73041-927d-42da-92cc-14242a397356 CRITICAL 9.8 The Email posts to subscribers plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.2… wordfence
51d3c250-301c-4f91-9fe5-56879a65fde7 CRITICAL 9.8 Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin… wordfence
51957ee1-a423-485b-8cfd-8eafaf6744e4
< 4.9.17.1
CRITICAL 9.8 The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers… wordfence
5183d676-eb91-4c03-8d12-c15c68839f02
< 4.02
CRITICAL 9.8 The SEMA API WordPress plugin through 3.64 does not properly sanitise and escape some parameters before using them in SQ… wordfence
515d6e6c-e20d-4fc4-9c56-80020196f2f0
< 1.7.2
CRITICAL 9.8 PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows re… wordfence
51424768-27c7-40b2-8d1c-838c419add8a
< 3.12
CRITICAL 9.8 SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execut… wordfence
← Prev 67 68 69 70 71 72 73 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top