🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 72 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5804da94-1dee-47f8-930b-c5413d5506b9
< 1.16
CRITICAL 9.8 The Direct Download for Woocommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in… — wordfence
57e37b16-230c-4cb5-96f7-4d5c20535e06
< 14.8.1
CRITICAL 9.8 The Simple Link Directory Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to 14.8.1 (… — wordfence
57be90d8-dab7-49c8-bcdf-32e967ee1716
< 2.6.5
CRITICAL 9.8 The bbPress plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to, and including,… — wordfence
57b97d58-28b6-4d50-81b5-a35c0b8cb180
< 2.5.3
CRITICAL 9.8 The HTML5 Radio Player - WPBakery Page Builder Addon plugin for WordPress is vulnerable to arbitrary file uploads due to… — wordfence
57a81776-643d-4057-9d81-b79ad396cced
< 1.18
CRITICAL 9.8 The RokNewsPager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… — wordfence
57704203-ed74-4100-900c-3f35c726e51e CRITICAL 9.8 Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/up… — wordfence
575d1353-70af-4200-9088-662f7a052b76
< 4.9.800
CRITICAL 9.8 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing… — wordfence
5754ffd6-81bb-491b-9272-627e8c52a22c
< 1.1.9
CRITICAL 9.8 The "AllWebMenus WordPress Menu Plugin" plugin for WordPress is vulnerable to arbitrary file uploads due to missing file… — wordfence
57531d89-1f54-43f4-a19d-9fda5e69f2ad
< 3.1.4
CRITICAL 9.8 A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress Wo… — wordfence
57450aba-ba77-46f2-95b8-b886f4cc14fe CRITICAL 9.8 The Plugin Name: Sovratec Case Management plugin for WordPress is vulnerable to arbitrary file uploads in all versions … — wordfence
570f680b-b688-49ad-9eed-0bc966a4cdf7 CRITICAL 9.8 The Faction theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.1.1. This is d… — wordfence
56f13af3-71b6-42d4-9fda-a75778f32091
< 3.4.31
CRITICAL 9.8 The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in… — wordfence
5683f121-a670-4b16-ac0f-c2cc569c05d4 CRITICAL 9.8 The Javo Core plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.0.0.26… — wordfence
56758c67-5df2-4e28-8095-a73151f9cb8c
< 1.2.11
CRITICAL 9.8 The Hara theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.10. This makes … — wordfence
56465338-f9be-49c5-8125-c6729287d590
< 1.7.7
CRITICAL 9.8 The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and Java… — wordfence
562d0052-7f1a-441b-9ff7-1c8bcb4b74b4
< 5.8.3
CRITICAL 9.8 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ‘billing_f… — wordfence
560b175b-ce2a-4161-aa6b-cd11d1377314 CRITICAL 9.8 The Satoshi theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the uplo… — wordfence
55fd9199-66ab-4a43-ba2e-bea1467bf744 CRITICAL 9.8 The Drop Uploader for CF7 - Drag&Drop File Uploader Addon plugin for WordPress is vulnerable to arbitrary file uploads d… — wordfence
55f507c4-8589-4fdb-92c2-935d38054817
< 1.0.6
CRITICAL 9.8 The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php. — wordfence
55e0f0df-7be2-4e18-988c-2cc558768eff
< 5.9.9
CRITICAL 9.8 The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to,… — wordfence
55abf798-f336-4262-9f52-4526a4bae15a CRITICAL 9.8 The Genesis Simple Love plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… — wordfence
55a0b4ad-de5e-4203-a702-d498bf566165
< 1.2.8
CRITICAL 9.8 SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary… — wordfence
5566a55e-81bb-4e14-98e1-1a548541e243
< 1.5.6
CRITICAL 9.8 The Form Block plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the f… — wordfence
554a314c-9e8e-4691-9792-d086790ef40f
< 4.24.12
CRITICAL 9.8 The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.2… — wordfence
552ec9fc-5bff-4bee-be04-39892c89cd59
< 1.2.0
CRITICAL 9.8 The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the … — wordfence
← Prev 69 70 71 72 73 74 75 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top