๐Ÿ›ก๏ธ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 73 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4a263b74-e9ae-4fd2-be9b-9b8e9eee5982
< 1.5.6
CRITICAL 9.8 The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
4a154c3f-e2c4-454d-94f9-539d8b289e4e
< 3.1.4
CRITICAL 9.8 The Ajar in5 Embed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… wordfence
49ea8af1-7171-4498-bfb0-bb3cbd72e6f3
< 5.1
CRITICAL 9.8 The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters befo… wordfence
49e133c9-5d3b-4a2a-8385-e2db44baa217
< 1.5.4
CRITICAL 9.8 The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and excluding, 1.5.4. Thi… wordfence
49cac6e5-c224-49f3-9f3d-07b07fc5e4cc
< 3.15.2
CRITICAL 9.8 The User Profile Builder โ€“ Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… wordfence
49ca1e15-b015-4e9e-bb79-be3968689609 CRITICAL 9.8 The Userpro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.1.9. This mak… wordfence
49ae7971-7bdf-4369-b04b-fb48ea5b9518
< 2.6.1
CRITICAL 9.8 The ็ฎ€ๆ•ฐ้‡‡้›†ๅ™จ (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… wordfence
496b1c3a-7fbb-4088-9936-6b023718946d
< 3.4.22
CRITICAL 9.8 The My Calendar plugin for WordPress is vulnerable to [blind|generic|time-based] SQL Injection via the 'from' and 'to' p… wordfence
494ef738-c900-4d00-8739-3b261586d4ff CRITICAL 9.8 The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0.… wordfence
494c780d-5441-407d-8947-e56d7cac32d6
< 3.9.8
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'store_id' parameter in… wordfence
491f44fc-712c-4f67-b5c2-a7396941afc1
< 3.6.1
CRITICAL 9.8 The Post SMTP โ€“ Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable … wordfence
48f7ad3b-608b-4802-b7ab-fad4c449cc62
< 2.6.1.4
CRITICAL 9.8 The SP Projects & Document Manager plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and i… wordfence
48e7acf2-61d4-4762-8657-0701910ce69b
< 0.0.9.19
CRITICAL 9.8 The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of … wordfence
48add930-a350-4828-84a0-e1207a9b239b
< 3.26
CRITICAL 9.8 The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to Remote Code Execution in all … wordfence
48950965-f7da-42af-9f9a-4bf7fd33be45
< 7.0
CRITICAL 9.8 The AR for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
48949329-8918-4d37-9f3a-1005e99d7e4d
< 1.7.0
CRITICAL 9.8 The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before u… wordfence
4893d7a7-6e37-4b58-b7ae-53feb0c85ff5 CRITICAL 9.8 The Uploadify plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'p… wordfence
4848292a-0378-4e0c-a95f-3232c5ce9b9f CRITICAL 9.8 The The Business theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.1 via d… wordfence
4830fb09-c138-4316-bdde-c233d58b0d91
< 5.1.9
CRITICAL 9.8 The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthenticated account … wordfence
481c738e-d544-4587-8632-e85a7ddd8b14
< 3.6.17
CRITICAL 9.8 The WatchTowerHQ plugin for WordPress is vulnerable to a type juggling issue in versions up to, and including, 3.6.16. T… wordfence
4770441f-5d8b-4edb-93e3-d2d73f145d26
< 2.0.9
CRITICAL 9.8 SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allow… wordfence
476df648-5024-42af-9bbd-a5a98e79453f
< 1.8.5
CRITICAL 9.8 The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
4750b57e-7d8d-49d7-bbbf-46483eb97bd9 CRITICAL 9.8 The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This … wordfence
474ad5a5-6384-41cb-a60b-e25477d48ad7 CRITICAL 9.8 upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via… wordfence
4712b12f-097b-4106-b2ba-e4c6cb7c32c2
< 1.0.1
CRITICAL 9.8 The WP-Mobile-BankID-Integration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and exclu… wordfence
← Prev 70 71 72 73 74 75 76 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top