πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 74 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
525b466d-137a-467b-8b49-e51393a73866 CRITICAL 9.8 The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in ver… — wordfence
523b5dd3-eb73-4156-ad2b-4d532e8d40f3
< 2.6.60
CRITICAL 9.8 The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to privilege escalation in all versi… — wordfence
522ecc1c-5834-4325-9234-79cf712213f3
< 1.7.0.13
CRITICAL 9.8 The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu… — wordfence
5228221f-b0b4-4faf-bde6-07666a96a278
< 3.6.3
CRITICAL 9.8 The Order Notification for WooCommerce – Get Audio Alert on new Orders plugin for WordPress is vulnerable to Remote Co… — wordfence
521b1786-3527-4b4e-b1c4-ff4fbfed8107 CRITICAL 9.8 The My Reading Library plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0 … — wordfence
52198053-206c-4002-8e26-dd5b4850e151
< 1.6.30
CRITICAL 9.8 The SalesKing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.15. This … — wordfence
520c1e8b-d0c1-4201-90bf-0cefab9af7e0 CRITICAL 9.8 The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all ver… — wordfence
5205fcde-2e6c-49de-b132-1ebefcd1ba59
< 1.4.4
CRITICAL 9.8 Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote att… — wordfence
51fc7d47-2a0f-4713-9859-120321aa32dc
< 3.3.7
CRITICAL 9.8 The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account take… — wordfence
51f73041-927d-42da-92cc-14242a397356 CRITICAL 9.8 The Email posts to subscribers plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.2… — wordfence
51d3c250-301c-4f91-9fe5-56879a65fde7 CRITICAL 9.8 Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin… — wordfence
51957ee1-a423-485b-8cfd-8eafaf6744e4
< 4.9.17.1
CRITICAL 9.8 The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers… — wordfence
5183d676-eb91-4c03-8d12-c15c68839f02
< 4.02
CRITICAL 9.8 The SEMA API WordPress plugin through 3.64 does not properly sanitise and escape some parameters before using them in SQ… — wordfence
515d6e6c-e20d-4fc4-9c56-80020196f2f0
< 1.7.2
CRITICAL 9.8 PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows re… — wordfence
51424768-27c7-40b2-8d1c-838c419add8a
< 3.12
CRITICAL 9.8 SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execut… — wordfence
50bdca4a-23c0-46aa-8c08-5987a2e28604
< 9.10.0
CRITICAL 9.8 The Private Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.9… — wordfence
50bcea94-b12a-4b31-b0c1-bba834ea9bd0
< 2.9.8.6
CRITICAL 9.8 The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of unt… — wordfence
509c881d-22bc-473f-b57b-4ec3ddf6abaf CRITICAL 9.8 The fMoblog plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and including,… — wordfence
5093d787-0357-4c28-9d27-8335b10fc499
< 1.2.54
CRITICAL 9.8 The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validat… — wordfence
508ff025-d1ab-4c8d-ac39-078023c4b5ce
< 1.6.8
CRITICAL 9.8 The All Post Contact Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… — wordfence
508b6466-2786-4d6b-9ab2-772050af4803
< 3.1.0.4
CRITICAL 9.8 The Easy Digital Downloads plugin for WordPress is vulnerable to SQL Injection in versions before 3.1.0.4 via the 's' pa… — wordfence
505b797f-f812-4da3-91c3-44f27a240ec2 CRITICAL 9.8 The The E-Commerce ERP: Purchasing, Inventory, Fulfillment, Manufacturing, BOM, Accounting, Sales Analysis plugin for Wo… — wordfence
505b1f87-52c6-439c-a108-e2003971dc07
< 1.5.2
CRITICAL 9.8 An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Un… — wordfence
50537e01-834e-4247-a80f-daa114eedcf1
< 2.5.2
CRITICAL 9.8 The Resume Submissions & Job Postings plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… — wordfence
504476f8-3583-448b-80fd-ed03b672a4e8
< 2.3.0
CRITICAL 9.8 The Easy Real Estate plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.… — wordfence
← Prev 71 72 73 74 75 76 77 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top