🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,406
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,406 vulnerabilities found (page 72 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4d79df74-bb28-412b-bba1-9f8a40ae981d
< 1.2.25
CRITICAL 9.8 The Appointment Booking Calendar plugin for WordPress is vulnerable to generic SQL Injection via any of the 'specialDat… wordfence
4d739821-569d-42d7-a4c5-70e32d5d41a1
< 5.2.9
CRITICAL 9.8 The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all version… wordfence
4d476336-e997-4379-a8f6-963ae22b2417 CRITICAL 9.8 The Relais 2FA plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0. This i… wordfence
4d3fd9b8-b9b7-4884-9188-6bf255058323
< 1.3.59
CRITICAL 9.8 The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is v… wordfence
4d38167c-47f8-473c-94de-91d9b439ddde
< 7.6
CRITICAL 9.8 The Indeed Membership Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
4d0a3cad-baa6-4de3-9420-c2d575dfd868 CRITICAL 9.8 Multiple plugins by itayamar for WordPress have been compromised via a supply chain attack. This is due to an abandoned … wordfence
4d052f3e-8554-43f0-a5ae-1de09c198d7b
< 3.7.8
CRITICAL 9.8 The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to,… wordfence
4ce039cd-2662-4cc3-9d38-932be7b7726d
< 3.8.8
CRITICAL 9.8 The PayU CommercePro Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inclu… wordfence
4cb77a63-360b-4917-8a3c-263f5282742c
< 2.0.3
CRITICAL 9.8 The Pricing Deals for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'term' parameter in versio… wordfence
4cada002-1fae-43fa-b1e0-e71afb223c53
< 1.3.1
CRITICAL 9.8 The clanora theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… wordfence
4c8f2872-06ff-41a2-b601-77a47470de0c
< 4.0.4
CRITICAL 9.8 The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i… wordfence
4c747e6f-31fc-41b0-ba62-f009b5483696
< 4.4.1
CRITICAL 9.8 The package simple-git is vulnerable to Remote Code Execution in versions before 3.15.0 when the ext transport protocol … wordfence
4c64089a-929c-4a36-8aa8-61a5c9e8562b
< 5.4.15
CRITICAL 9.8 The Woffice CRM theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an… wordfence
4c5c757f-8546-4a95-a9f4-92d59106aa83
< 1.3.0
CRITICAL 9.8 The PowerPack for LearnDash plugin for WordPress is vulnerable to unauthorized modification of data that can lead to pri… wordfence
4c367565-75f7-4dd7-a2f1-111df581bd7a
< 1.1.8
CRITICAL 9.8 The Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress plugin for WordPress is vulnerable… wordfence
4bbb0146-436f-42fa-802b-cdcf39ae97db
< 4.0.27
CRITICAL 9.8 The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorize… wordfence
4b8d057b-1909-46d4-8e0a-d5c7c9f7001c
< 3.3.1
CRITICAL 9.8 The Relevanssi plugin for WordPress is vulnerable to SQL Injection via the ‘category_name’ parameter in versions up … wordfence
4b704c42-181b-47cb-9df8-3b82f7b830e1
< 1.1.24
CRITICAL 9.8 The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CV… wordfence
4b585243-943d-48d4-bee3-407ff3ae8078
< 1.9.9.5
CRITICAL 9.8 The VibeBP plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.9.4.1. T… wordfence
4b40e33b-4aa8-4378-b044-a8a636d34f73 CRITICAL 9.8 The Referrer Detector plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.1… wordfence
4b39c8e1-f2b7-436d-97d1-2d503d7ac835
< 3.2.5
CRITICAL 9.8 The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection. wordfence
4b2d685f-0426-4837-bf96-07ebda499bed CRITICAL 9.8 The Blog Designer PRO for WordPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in… wordfence
4b0e763e-f03e-41fb-8c6c-4de5d3acae00
< 2.6.7
CRITICAL 9.8 The Ultimate Member plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.6. … wordfence
4ad379ad-8733-4015-a892-375604339695
< 15.8
CRITICAL 9.8 SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbi… wordfence
4aa89fab-b6fe-423a-a7f5-dbe6c92d1b56
< 3.8.7.6
CRITICAL 9.8 SQL injection vulnerability in the WP e-Commerce plugin before 3.8.7.6 for WordPress allows remote attackers to execute … wordfence
← Prev 69 70 71 72 73 74 75 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top