πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 75 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
50349086-e7b0-4f73-8722-1367cc05180e
< 3.10.4
CRITICAL 9.8 The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.10.1. T… — wordfence
5016ecf2-6016-4a46-8e16-30e9f79344e4
< 2.15.0
CRITICAL 9.8 The WooCommerce Online Product Designer plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up t… — wordfence
4ff3b4f1-dd36-43d0-b472-55a940907437
< 5.1.9
CRITICAL 9.8 The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. Thi… — wordfence
4fd67a02-b0fb-4c4f-9564-c3ee0180e79c
< 2.2
CRITICAL 9.8 The Couponis Demo plugin for WordPress is vulnerable to SQL Injection in versions up to 2.2 due to insufficient escaping… — wordfence
4fb0195a-077e-4f43-9294-1e5ecad7eb82
< 3.5.13
CRITICAL 9.8 The SysBasics Easy Checkout Field Editor, Fees & Discounts plugin for WordPress is vulnerable to arbitrary file uploads … — wordfence
4fa5ba38-0b6f-4eec-aac1-1c3806f0d040
< 3.0.3
CRITICAL 9.8 The "Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension" plugin for WordPress is vulne… — wordfence
4fa04a97-0be1-4710-ae97-5820ccbddc1e
< 3.35.0
CRITICAL 9.8 An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.ll… — wordfence
4f95bcc3-354e-4016-9a17-945569b076b6
< 32.0.19
CRITICAL 9.8 The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing … — wordfence
4f4ebf09-b089-4118-a0ee-399243253f9c
< 3.3.2
CRITICAL 9.8 The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive … — wordfence
4f3900c7-2acb-4031-9854-b0b13e172e1f
< 5.7.4
CRITICAL 9.8 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File In… — wordfence
4ed8866c-d8f1-4c5e-aba0-b3a0677c8efc
< 3.0
CRITICAL 9.8 The Scripts Organizer plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, but not including,… — wordfence
4ed0ea4a-9cbf-4033-a31f-6cb954e8ce01
< 3.4
CRITICAL 9.8 The IMITHEMES Listing plugin is vulnerable to privilege escalation via account takeover in all versions up to, and inclu… — wordfence
4ebb766a-44e9-460c-be84-356b7403e593
< 5.1.7
CRITICAL 9.8 The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i… — wordfence
4ea89a6e-e089-4e8d-afd8-2a217f6910a6 CRITICAL 9.8 The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Incl… — wordfence
4e9c5e89-9ead-477b-980b-9e48969ad0cf CRITICAL 9.8 The Tajer for WordPress is vulnerable to arbitrary file uploads due to inclusion of a vulnerable version of the Blueimp … — wordfence
4e444a30-11c5-4219-b4fe-635084cbac3a
< 3.8.0
CRITICAL 9.8 The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account… — wordfence
4db1ee2b-d8ed-4f2a-8de5-81abeafa2f9d CRITICAL 9.8 The Rich Widget plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … — wordfence
4d79df74-bb28-412b-bba1-9f8a40ae981d
< 1.2.25
CRITICAL 9.8 The Appointment Booking Calendar plugin for WordPress is vulnerable to generic SQL Injection via any of the 'specialDat… — wordfence
4d739821-569d-42d7-a4c5-70e32d5d41a1
< 5.2.9
CRITICAL 9.8 The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all version… — wordfence
4d476336-e997-4379-a8f6-963ae22b2417 CRITICAL 9.8 The Relais 2FA plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0. This i… — wordfence
4d438635-db41-4b7a-a57f-eb2f746ad2e1 CRITICAL 9.8 The ImproveSEO plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.11. Thi… — wordfence
4d3fd9b8-b9b7-4884-9188-6bf255058323
< 1.3.59
CRITICAL 9.8 The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is v… — wordfence
4d38167c-47f8-473c-94de-91d9b439ddde
< 7.6
CRITICAL 9.8 The Indeed Membership Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… — wordfence
4d0a3cad-baa6-4de3-9420-c2d575dfd868 CRITICAL 9.8 Multiple plugins by itayamar for WordPress have been compromised via a supply chain attack. This is due to an abandoned … — wordfence
4d052f3e-8554-43f0-a5ae-1de09c198d7b
< 3.7.8
CRITICAL 9.8 The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to,… — wordfence
← Prev 72 73 74 75 76 77 78 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top