πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 71 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5ad12146-200b-48e5-82de-7572541edcc4
< 4.9.1
CRITICAL 9.8 The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and includin… — wordfence
5ab2c74d-b83b-40ea-951c-83aeb76a7515 CRITICAL 9.8 The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass… — wordfence
5a97877b-fb4d-4e87-bcff-56be65fee6ce
< 20190426
CRITICAL 9.8 The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… — wordfence
5a7f869d-e915-4048-b0e1-36cf25e732f9 CRITICAL 9.8 The Audio Record plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… — wordfence
5a5f31ad-75f9-4534-a8a6-e76f9aefbd80 CRITICAL 9.8 The Hospital Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing… — wordfence
5a5d5dbd-36f0-4886-adf8-045ec9c2e306
< 3.6
CRITICAL 9.8 The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … — wordfence
5a0612de-0f85-44d3-9b81-1a6a7720a03a
< 7.20.01
CRITICAL 9.8 The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Remote Code Execution… — wordfence
59be1fc7-2854-404d-8e9d-dd9bd26e6a2c
< 3.11
CRITICAL 9.8 The Rencontre – Dating Site plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and in… — wordfence
59aebe74-cf53-49f4-8f20-ebb5503d7dbd
< 5.9.9.7
CRITICAL 9.8 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via… — wordfence
59a645e4-2a23-4440-a463-fa197dfa20b2 CRITICAL 9.8 The WA Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the β€˜wa_forms_Id’ parameter in v… — wordfence
59a05868-7457-4fb1-845e-bf7044d5cb81
< 2.2.2
CRITICAL 9.8 The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader… — wordfence
599c6984-5d52-4d0f-86a1-b88f6c9797ed
< 2.2.8
CRITICAL 9.8 The Buddyforms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.2.7 due to insuff… — wordfence
598fffcd-0318-4e41-8837-f65761390c19
< 3.1.5
CRITICAL 9.8 The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers. — wordfence
595fac73-c583-4712-ad37-fbd0fa3eb147
< 1.3.6
CRITICAL 9.8 SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header. — wordfence
5933fc11-8f06-4d58-9483-d06997e5d731
< 0.3.0.04
CRITICAL 9.8 The Filebase Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includi… — wordfence
58f8bba4-1be5-4111-aa41-d076a6f06948
< 1.6.4
CRITICAL 9.8 The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_fa… — wordfence
58ea0c9c-f63d-4c31-b02e-a86d5fe732aa CRITICAL 9.8 The Flash News Theme for WordPress is vulnerable to Cross-Site Scripting in all versions due to inclusion of a vulnerabl… — wordfence
58bd4a75-8e24-4810-8b9d-c9ffad1c2208
< 1.5
CRITICAL 9.8 The WP Donate plugin for WordPress is vulnerable to SQL Injection in donate-display.php in versions up to, and including… — wordfence
589fa6f2-fa60-4bdc-9692-50d5591ceb93 CRITICAL 9.8 The FlipBook plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /fl… — wordfence
588ece40-a848-4b2c-9db5-e63e0d11dda0
< 2.0.2
CRITICAL 9.8 The WP e-Commerce – Store Toolkit plugin for WordPress is vulnerable to authorization bypass due to a missing capabili… — wordfence
5881d16c-84e8-4610-8233-cfa5a94fe3f9
< 3.9.2
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This… — wordfence
5875a4c2-a309-41fb-8845-2935511ec6c0
< 2.1.6
CRITICAL 9.8 The UnGallery plugin for WordPress is vulnerable to Command Injection in versions before 2.1.6 via the 'search' paramete… — wordfence
586250e9-bc35-4c9d-b558-7346efd4dce9
< 2.9.23.1
CRITICAL 9.8 The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation … — wordfence
5846b5d9-5b69-47b0-b787-6a3416a5076e
< 1.3.2
CRITICAL 9.8 The WpBookingly plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.1 via d… — wordfence
580f5cd1-2cda-4e8e-81b5-36ce39ebd907 CRITICAL 9.8 The Zarzadzanie Kontem plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … — wordfence
← Prev 68 69 70 71 72 73 74 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top