🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 70 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5d7b75a4-67b4-4347-91a6-dbf98da5ceaf CRITICAL 9.8 The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Res… — wordfence
5d5c553f-247d-4feb-8027-822cfaca4adf
< 2.4
CRITICAL 9.8 The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to mis… — wordfence
5d371a8e-2997-4be3-afd9-60f752a6721c
< 5.2.7
CRITICAL 9.8 The OMGF Pro plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 5… — wordfence
5d07d5e9-be7c-4c16-b931-d909ed8be361
< 1.11.4
CRITICAL 9.8 The Login with WHMCS plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 1.11.3… — wordfence
5ce4b3cf-1c36-4596-b113-055945fceeb6
< 1.6.10
CRITICAL 9.8 The Pix 4x sem juros - Pagaleve plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… — wordfence
5ca1c55a-cd4e-429a-ab74-dd1bad1a65f5
< 3.1.5
CRITICAL 9.8 The SupportCandy plugin for WordPress is vulnerable to SQL injection via the 'parse_user_filters' function in versions u… — wordfence
5c9a23a3-5eb5-4f5b-bf32-c9d163426f29
< 5.0.12
CRITICAL 9.8 The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, … — wordfence
5c9320f9-2e1a-4d76-850b-fa6fb68cd09f CRITICAL 9.8 The Realty Workstation plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including,… — wordfence
5c79d861-e2e8-4fca-883f-79401544b0b1 CRITICAL 9.8 The RLSWordPressSearch plugin for WordPress is vulnerable to generic SQL Injection via the 'agentid' parameter in the 'r… — wordfence
5c75c156-225c-465a-8d03-35a6669e9c04
< 1.0.12
CRITICAL 9.8 The Calculated Fields Form plugin for WordPress is vulnerable to SQL Injection via Cross-Site Request Forgery in version… — wordfence
5c601f75-3ee2-47ed-8d67-67fac4403a5d CRITICAL 9.8 The JSON Options plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.0.4… — wordfence
5c42a966-0035-4c12-8aa1-226a0157d98f
< 3.8.9.1
CRITICAL 9.8 The WP eCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ‘view_purchlogs_by_status’ para… — wordfence
5c024c77-31a8-45b8-9fcb-7ba729bec32c CRITICAL 9.8 The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter. — wordfence
5bf6d60f-57ac-4cbc-895f-a7db548cbf67
< 1.2.0
CRITICAL 9.8 The Api2Cart Bridge Connector plugin for WordPress is vulnerable to arbitrary file uploads due to missing or incorrect f… — wordfence
5bef5bd3-8ec9-4a5b-bcdd-98952c7ef390
< 3.16.1
CRITICAL 9.8 The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the … — wordfence
5bde312b-abbb-4e8e-91c6-a42dadbaedb5
< 14.4.5
CRITICAL 9.8 The StoreKeeper for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… — wordfence
5b7c8a73-92da-4d2f-a37c-2ac380e56c5f CRITICAL 9.8 The Energia - Renewable Energy WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to missin… — wordfence
5b75c322-539d-44e9-8f26-5ff929874b67
< 1.2.6
CRITICAL 9.8 The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.… — wordfence
5b67a9ce-44ad-4438-a545-84ca69e2ef47
< 1.0.7
CRITICAL 9.8 The Fable Extra plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.6. This… — wordfence
5b5ae0ae-1272-4bac-867f-4ff84155799e
< 1.0.8
CRITICAL 9.8 The HAPPY – Helpdesk Support Ticket System plugin for WordPress is vulnerable to Remote Code Execution in all versions… — wordfence
5b546d24-82c1-4598-8926-6e73a4784b38
< 4.6.6
CRITICAL 9.8 The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation… — wordfence
5b53fa6f-7fb8-4643-a365-7630102e7e46
< 1.4.7
CRITICAL 9.8 The BigContact Contact Page plugin for WordPress is vulnerable to SQL Injection via several parameters in versions befor… — wordfence
5b39be2a-0769-4f3e-885f-a534682670ad CRITICAL 9.8 The WPCHURCH plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7.0. This ma… — wordfence
5b07ea6a-511d-44ab-b0b7-5124702ad47d
< 3.9.1
CRITICAL 9.8 The Login as User or Customer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and inc… — wordfence
5b00cf9b-60c3-44a4-98a7-ee0f3e763c87
< 3.4.11
CRITICAL 9.8 The Sunshine Photo Cart plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.4… — wordfence
← Prev 67 68 69 70 71 72 73 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top