πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,405
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,405 vulnerabilities found (page 71 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
50bdca4a-23c0-46aa-8c08-5987a2e28604 CRITICAL 9.8 The Private Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.9… wordfence
50bcea94-b12a-4b31-b0c1-bba834ea9bd0
< 2.9.8.6
CRITICAL 9.8 The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of unt… wordfence
509c881d-22bc-473f-b57b-4ec3ddf6abaf CRITICAL 9.8 The fMoblog plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and including,… wordfence
5093d787-0357-4c28-9d27-8335b10fc499
< 1.2.54
CRITICAL 9.8 The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validat… wordfence
508ff025-d1ab-4c8d-ac39-078023c4b5ce CRITICAL 9.8 The All Post Contact Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
508b6466-2786-4d6b-9ab2-772050af4803
< 3.1.0.4
CRITICAL 9.8 The Easy Digital Downloads plugin for WordPress is vulnerable to SQL Injection in versions before 3.1.0.4 via the 's' pa… wordfence
505b797f-f812-4da3-91c3-44f27a240ec2 CRITICAL 9.8 The The E-Commerce ERP: Purchasing, Inventory, Fulfillment, Manufacturing, BOM, Accounting, Sales Analysis plugin for Wo… wordfence
505b1f87-52c6-439c-a108-e2003971dc07
< 1.5.2
CRITICAL 9.8 An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Un… wordfence
50537e01-834e-4247-a80f-daa114eedcf1
< 2.5.2
CRITICAL 9.8 The Resume Submissions & Job Postings plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… wordfence
504476f8-3583-448b-80fd-ed03b672a4e8
< 2.3.0
CRITICAL 9.8 The Easy Real Estate plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.… wordfence
50349086-e7b0-4f73-8722-1367cc05180e
< 3.10.4
CRITICAL 9.8 The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.10.1. T… wordfence
4ff3b4f1-dd36-43d0-b472-55a940907437
< 5.1.9
CRITICAL 9.8 The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. Thi… wordfence
4fd67a02-b0fb-4c4f-9564-c3ee0180e79c
< 2.2
CRITICAL 9.8 The Couponis Demo plugin for WordPress is vulnerable to SQL Injection in versions up to 2.2 due to insufficient escaping… wordfence
4fb0195a-077e-4f43-9294-1e5ecad7eb82
< 3.5.13
CRITICAL 9.8 The SysBasics Easy Checkout Field Editor, Fees & Discounts plugin for WordPress is vulnerable to arbitrary file uploads … wordfence
4fa5ba38-0b6f-4eec-aac1-1c3806f0d040
< 3.0.3
CRITICAL 9.8 The "Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension" plugin for WordPress is vulne… wordfence
4fa04a97-0be1-4710-ae97-5820ccbddc1e
< 3.35.0
CRITICAL 9.8 An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.ll… wordfence
4f95bcc3-354e-4016-9a17-945569b076b6
< 32.0.19
CRITICAL 9.8 The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing … wordfence
4f3900c7-2acb-4031-9854-b0b13e172e1f
< 5.7.4
CRITICAL 9.8 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File In… wordfence
4ed8866c-d8f1-4c5e-aba0-b3a0677c8efc
< 3.0
CRITICAL 9.8 The Scripts Organizer plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, but not including,… wordfence
4ed0ea4a-9cbf-4033-a31f-6cb954e8ce01
< 3.4
CRITICAL 9.8 The IMITHEMES Listing plugin is vulnerable to privilege escalation via account takeover in all versions up to, and inclu… wordfence
4ebb766a-44e9-460c-be84-356b7403e593
< 5.1.7
CRITICAL 9.8 The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i… wordfence
4ea89a6e-e089-4e8d-afd8-2a217f6910a6 CRITICAL 9.8 The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Incl… wordfence
4e9c5e89-9ead-477b-980b-9e48969ad0cf CRITICAL 9.8 The Tajer for WordPress is vulnerable to arbitrary file uploads due to inclusion of a vulnerable version of the Blueimp … wordfence
4e444a30-11c5-4219-b4fe-635084cbac3a
< 3.8.0
CRITICAL 9.8 The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account… wordfence
4db1ee2b-d8ed-4f2a-8de5-81abeafa2f9d CRITICAL 9.8 The Rich Widget plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … wordfence
← Prev 68 69 70 71 72 73 74 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top