πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 73 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
54f1ebfb-67f1-461d-91f1-269b0a2c0653
< 1.0.3
CRITICAL 9.8 The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and … — wordfence
54c1eb7b-c3fe-4975-9f51-df3aba53fe46
< 2.4.5
CRITICAL 9.8 The VR Calendar plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.4.4. … — wordfence
54b079b5-35e4-4d65-97ce-6d0d2053886d
< 1.0.24
CRITICAL 9.8 The Agency Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.… — wordfence
54901d01-241a-4027-ba72-2b983608f9c6
< 4.5.2
CRITICAL 9.8 The Advanced Post Manager for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.5.1 … — wordfence
54553005-1869-4334-92ec-e37e8935d769
< 2.1
CRITICAL 9.8 SQL injection vulnerability in Apptha WordPress Video Gallery 2.0, 1.6, and earlier for WordPress allows remote attacker… — wordfence
544b09a2-dfd4-4dee-8687-fe86cdc65f30
< 1.4.6
CRITICAL 9.8 The Material Dashboard plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions u… — wordfence
541551d8-5510-43ff-b685-783d0d94c4bb CRITICAL 9.8 The moveto plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in an unknow… — wordfence
5413ae2a-9afa-4ff6-b241-73b446881185 CRITICAL 9.8 The MyPixs plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.3 via the 'dow… — wordfence
540d444f-7a6c-4c14-a9c7-52209ad59a11
< 1.5.1
CRITICAL 9.8 The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key which makes it possible for an u… — wordfence
540ac650-6bfd-4ee2-b3c8-b6444a209b6a
< 2.0.9
CRITICAL 9.8 Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote … — wordfence
54041d74-6d2e-4a70-aa35-46619afb9d8c CRITICAL 9.8 The hockeydata LOS plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.4. T… — wordfence
53eba5b4-7cc0-48e1-bb9c-6ed3207151ab
< 6.6.1
CRITICAL 9.8 The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… — wordfence
53e83037-2cc5-4dc9-b55d-03829df12a65
< 2.8.8
CRITICAL 9.8 The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc… — wordfence
53cc91fa-51fd-4d16-b740-a48f8d446b5d
< 2.8.5
CRITICAL 9.8 The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable … — wordfence
53b5a052-6e84-4eb5-a7f4-4e32f757f4d6
< 3.0.0
CRITICAL 9.8 The Smush – Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to Cross-Site Scripting le… — wordfence
5391ad0a-a5c7-4fd8-b94e-9236cca41568 CRITICAL 9.8 The JS Job Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… — wordfence
535f9f16-a7fc-40fe-8be1-90c542675cc4 CRITICAL 9.8 The Woolook plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.0. This mak… — wordfence
53580b24-c0a7-4578-bb11-5952ebcacc42 CRITICAL 9.8 The UltimateWoo plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.1.10 via … — wordfence
531e6da9-a24c-4b75-b909-ec4614075044 CRITICAL 9.8 The PIMP theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7 via deseria… — wordfence
531d57c4-404a-475e-842a-08425959e150 CRITICAL 9.8 The vBSSO-lite plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an… — wordfence
52db8d41-859a-4d68-8b83-3d3af8f1bf64
< 1.2.6
CRITICAL 9.8 The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on severa… — wordfence
52d05693-469f-4fd9-800a-d8b9b94760fb CRITICAL 9.8 The WooCommerce Designer Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… — wordfence
52c19707-df18-4239-af46-12ea5ee86a4b
< 4.03.33
CRITICAL 9.8 The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin … — wordfence
529c5785-214e-41e7-8cf3-4ff3d256e27c CRITICAL 9.8 SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers t… — wordfence
5284aef6-8fcd-4a75-a189-b2223bb83b60 CRITICAL 9.8 The CBX Poll plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.7 via dese… — wordfence
← Prev 70 71 72 73 74 75 76 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top