🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 74 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
470fbac6-45bf-400e-b415-32e7989abbad
< 3.0
CRITICAL 9.8 The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups funct… wordfence
470285d6-b309-409c-b2c3-8766a0cf9e98
< 3.1.5
CRITICAL 9.8 The ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks plugin for WordPress is vulnerable to PHP Object Inj… wordfence
46f3cc62-c2d8-45af-bb92-c2040789cbc0
< 2.2.1
CRITICAL 9.8 The HT Mega plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.2.0. This is… wordfence
46f31a60-0a0e-449d-a10a-3cafd0492a9c CRITICAL 9.8 The Recently Viewed Products plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… wordfence
46d83cc9-0094-4f08-a8f2-270d5dbd66ac
< 2.4.1
CRITICAL 9.8 The EventON plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4. This makes… wordfence
46b3f3fb-5bd5-4af4-a281-647ad0b8e992
< 2.2.6
CRITICAL 9.8 The Google Map plugin for WordPress is vulnerable to blind SQL Injection via the ‘table’ parameter in versions up to… wordfence
46b3b01c-8739-4b51-be34-1dd3c50d772e
< 0.9.10
CRITICAL 9.8 WP-Syntax plugin 0.9.9 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbi… wordfence
46545227-3c04-40a4-a25c-8f43845e90d3
< 13.1.6
CRITICAL 9.8 The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t… wordfence
4624d197-db90-41ee-a3d5-a83a0dbf6b7c
< 0.15.2
CRITICAL 9.8 The Global Flash Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… wordfence
462125cd-c91a-44b1-9004-4a62f2aed52c CRITICAL 9.8 The Woocommerce Product Design plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… wordfence
45e0664a-385d-4879-acf6-46e837aaa03f CRITICAL 9.8 The kernel-theme theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the… wordfence
45d66743-300e-480d-98b8-99dc30b6e786
< 2.2.1
CRITICAL 9.8 The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.2.0. This… wordfence
45b6a72a-9aa9-4d77-b250-575d55538110
< 1.1.4
CRITICAL 9.8 PHP remote file inclusion vulnerability in actions.php in the Allwebmenus plugin 1.1.3 for WordPress allows remote attac… wordfence
45a778cc-0063-4c07-ae57-bd473976e68c
< 1.0.8
CRITICAL 9.8 The Ruza theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.7. This makes i… wordfence
4592fea7-65c4-45f6-8674-ae5f706db413 CRITICAL 9.8 The A/B Test for WordPress plugin for WordPress is vulnerable to Local File Inclusion via the 'action' parameter in the … wordfence
45760755-472a-4b5f-abdf-373173ef64d3
< 1.1.4
CRITICAL 9.8 The WP Smart Import plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.3. … wordfence
45531492-9238-4e2e-ad37-d0e5c457af07
< 1.9.9.1
CRITICAL 9.8 The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file up… wordfence
45240c80-44b3-45d6-b23e-0d4c29cca502
< 24.07.03
CRITICAL 9.8 The Docket Cache plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 24.07.02. … wordfence
451db756-9d62-4c8e-b735-e5e5207b81e3
< 1.5.0
CRITICAL 9.8 The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to time-based SQL Injection via the ‘con… wordfence
45163d7f-59c9-4bce-95a7-5b56e1cc018b
< 12.12
CRITICAL 9.8 The WP Symposium plugin for WordPress is vulnerable to various SQL Injections in versions up to, and including, 12.09 du… wordfence
44edf44b-5456-4c4b-86c3-80ad785cfb6a CRITICAL 9.8 The JS Job Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.2. T… wordfence
44e54ac5-8091-4154-a14c-5cd67647f722
< 3.1.4
CRITICAL 9.8 Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f… wordfence
44c96df2-530a-4ebe-b722-c606a7b135f9
< 1.6.2
CRITICAL 9.8 The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5.… wordfence
44ba3eee-525e-46ba-ae02-6f7a28f80c50
< 1.5.2
CRITICAL 9.8 An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum… wordfence
44a921e7-cce3-4347-968d-76dab243fcd6
< 2.4.3
CRITICAL 9.8 The Clone plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4… wordfence
← Prev 71 72 73 74 75 76 77 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top