🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 76 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4ce039cd-2662-4cc3-9d38-932be7b7726d
< 3.8.8
CRITICAL 9.8 The PayU CommercePro Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inclu… — wordfence
4cb77a63-360b-4917-8a3c-263f5282742c
< 2.0.3
CRITICAL 9.8 The Pricing Deals for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'term' parameter in versio… — wordfence
4cada002-1fae-43fa-b1e0-e71afb223c53
< 1.3.1
CRITICAL 9.8 The clanora theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… — wordfence
4c8f2872-06ff-41a2-b601-77a47470de0c
< 4.0.4
CRITICAL 9.8 The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i… — wordfence
4c747e6f-31fc-41b0-ba62-f009b5483696
< 4.4.1
CRITICAL 9.8 The package simple-git is vulnerable to Remote Code Execution in versions before 3.15.0 when the ext transport protocol … — wordfence
4c64089a-929c-4a36-8aa8-61a5c9e8562b
< 5.4.15
CRITICAL 9.8 The Woffice CRM theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an… — wordfence
4c5c757f-8546-4a95-a9f4-92d59106aa83
< 1.3.0
CRITICAL 9.8 The PowerPack for LearnDash plugin for WordPress is vulnerable to unauthorized modification of data that can lead to pri… — wordfence
4c367565-75f7-4dd7-a2f1-111df581bd7a
< 1.1.8
CRITICAL 9.8 The Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress plugin for WordPress is vulnerable… — wordfence
4c221909-bc1b-47e3-bfec-71b419f48ae3
< 2.0.2
CRITICAL 9.8 The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, … — wordfence
4bbb0146-436f-42fa-802b-cdcf39ae97db
< 4.0.27
CRITICAL 9.8 The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorize… — wordfence
4b8d057b-1909-46d4-8e0a-d5c7c9f7001c
< 3.3.1
CRITICAL 9.8 The Relevanssi plugin for WordPress is vulnerable to SQL Injection via the ‘category_name’ parameter in versions up … — wordfence
4b704c42-181b-47cb-9df8-3b82f7b830e1
< 1.1.24
CRITICAL 9.8 The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CV… — wordfence
4b585243-943d-48d4-bee3-407ff3ae8078
< 1.9.9.5
CRITICAL 9.8 The VibeBP plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.9.4.1. T… — wordfence
4b40e33b-4aa8-4378-b044-a8a636d34f73 CRITICAL 9.8 The Referrer Detector plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.1… — wordfence
4b39c8e1-f2b7-436d-97d1-2d503d7ac835
< 3.2.5
CRITICAL 9.8 The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection. — wordfence
4b2d685f-0426-4837-bf96-07ebda499bed CRITICAL 9.8 The Blog Designer PRO for WordPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in… — wordfence
4b0e763e-f03e-41fb-8c6c-4de5d3acae00
< 2.6.7
CRITICAL 9.8 The Ultimate Member plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.6. … — wordfence
4b0445ce-614b-4948-a48c-c1b95cc7f043
< 1.7.0
CRITICAL 9.8 Multiple Supsystic Pro plugins for WordPress contain backdoors in various versions. This is due to the vendors update se… — wordfence
4ad379ad-8733-4015-a892-375604339695
< 15.8
CRITICAL 9.8 SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbi… — wordfence
4aa89fab-b6fe-423a-a7f5-dbe6c92d1b56
< 3.8.7.6
CRITICAL 9.8 SQL injection vulnerability in the WP e-Commerce plugin before 3.8.7.6 for WordPress allows remote attackers to execute … — wordfence
4a47660e-67a6-42d4-a7ec-911dcf3e6e47
< 4.4.2
CRITICAL 9.8 The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress… — wordfence
4a263b74-e9ae-4fd2-be9b-9b8e9eee5982
< 1.5.6
CRITICAL 9.8 The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … — wordfence
4a154c3f-e2c4-454d-94f9-539d8b289e4e
< 3.1.4
CRITICAL 9.8 The Ajar in5 Embed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… — wordfence
4a1127af-74f6-4748-9aee-5a8c6c2766a4
< 4.21.1
CRITICAL 9.8 The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and includ… — wordfence
49ea8af1-7171-4498-bfb0-bb3cbd72e6f3
< 5.1
CRITICAL 9.8 The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters befo… — wordfence
← Prev 73 74 75 76 77 78 79 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top