🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 75 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
444fae52-ffcb-4502-a052-239693bfa326
< 4.2.2
CRITICAL 9.8 The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to arbitra… wordfence
440e34a2-0185-4294-b82d-a0249769731e
< 3.14.28
CRITICAL 9.8 The Flexmls® IDX plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.14.27 v… wordfence
43d1f708-58bd-4d42-b8dd-0c1247546577
< 1.4.3
CRITICAL 9.8 The Floating Social Media Links plugin for WordPress is vulnerable to Remote File Inclusion in versions before 1.4.3 via… wordfence
43cb0399-4add-43d5-863c-30e11803bd90
< 4.4.7
CRITICAL 9.8 The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover … wordfence
43b7e458-73d7-4a02-8184-081654a9f58e
< 1.1.5
CRITICAL 9.8 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… wordfence
43a64074-ca64-4c34-b467-06d1ad8c5aa0
< 5.10.0
CRITICAL 9.8 The Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.9.0… wordfence
438d73bb-80f1-460f-8c62-2a40856e4c29
< 5.0
CRITICAL 9.8 The Auto Affiliate Links plugin for WordPress is vulnerable to multiple SQL Injections via the 'aal_massstring' and 'aal… wordfence
437c88f8-9457-48e5-b10f-aa453720bc5a CRITICAL 9.8 The Zita Site Builder plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capabi… wordfence
436fc1c8-3141-445d-902e-f759feefe1cc CRITICAL 9.8 The Husker Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… wordfence
431b0f09-6b0a-4f67-bd39-38ee7d90eb07
< 1.0.15
CRITICAL 9.8 The Mail Picker plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.14 via … wordfence
42ff1e17-ccc2-478b-a3b5-88e3bea28a5e
< 1.44
CRITICAL 9.8 PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, wh… wordfence
42f5d834-d63c-4690-a03b-e573ce91465c CRITICAL 9.8 The WooCommerce Pickupp plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4… wordfence
4299e97c-3b91-4870-bafd-557b72b93b44
< 1.5.52
CRITICAL 9.8 SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable… wordfence
4280654a-9eab-4541-8b82-74086d37d928
< 3.2.1
CRITICAL 9.8 The CM Registration Pro plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.2… wordfence
427a788b-e9d9-422a-ab63-179f12860e4e
< 3.2.1
CRITICAL 9.8 The Traveler theme for WordPress is vulnerable to PHP Object Injection in versions up to 3.2.1 via deserialization of un… wordfence
4252c092-1276-4f69-88f9-cf78799c725c
< 4.0.27
CRITICAL 9.8 The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress … wordfence
42525101-6196-40b9-90e7-c7f1886ef247
< 2.9.21
CRITICAL 9.8 The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… wordfence
424ebeb4-eb53-4c87-9a86-aff1c784aa3c CRITICAL 9.8 The WordPress Spreadsheet plugin for WordPress is vulnerable to SQL Injection via the 'ss_id' parameter in versions up t… wordfence
4240c04b-cad3-496f-b12f-7718bb498fe0 CRITICAL 9.8 Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to s… wordfence
42378b83-2a39-4e5f-8671-ee4a44ee92a5
< 1.302
CRITICAL 9.8 The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowledge of an e… wordfence
42222c64-6492-4774-b5bc-8e62a1a328cf
< 2.11.0
CRITICAL 9.8 The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecu… wordfence
4221b33c-5cfa-48db-92bf-bf25ff3c5a5f
< 1.7.14
CRITICAL 9.8 The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file typ… wordfence
420580e1-b6cf-4fd7-87fd-e415b097f4c9 CRITICAL 9.8 The Davenport - Versatile Blog and Magazine WordPress Theme plugin for WordPress is vulnerable to Local File Inclusion i… wordfence
41cfe1d7-2fab-413c-80e5-40d77133d229
< 11.31.0
CRITICAL 9.8 The Knowledge Base for Documentation, FAQs with AI Assistance plugin for WordPress is vulnerable to PHP Object Injection… wordfence
41cf57ff-421d-4db2-894f-17f2c4d4b9ed
< 5.6.2
CRITICAL 9.8 The WooCommerce Payments plugin is vulnerable to authentication bypass via the determine_current_user_for_platform_check… wordfence
← Prev 72 73 74 75 76 77 78 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top