🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 76 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
41af6441-bc1d-4210-92f3-4c765fda6df9
< 1.9.13
CRITICAL 9.8 NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload wordfence
41a61c0f-fffb-4810-b44a-74cbc1192ecd CRITICAL 9.8 The HTML5 AV Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… wordfence
419a42eb-19ed-46a3-9da0-3fcd2c8e2527 CRITICAL 9.8 The Share Buttons – Social Media plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… wordfence
41800ea9-1ace-42fc-9e7f-d760a126342b
< 1.7
CRITICAL 9.8 The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and incl… wordfence
415c9658-bfb2-453b-a697-c63c08b0ca61
< 1.8.0
CRITICAL 9.8 The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Rem… wordfence
414636bc-3fab-41f9-9d4b-17ca1ac8a3df
< 1.4.72
CRITICAL 9.8 The Motors plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.71. This mak… wordfence
4124003c-4864-48f1-acba-9a613d9c99ae
< 5.4
CRITICAL 9.8 The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including,… wordfence
4122a963-b8e2-448a-b268-3192613fa3df
< 4.1.4
CRITICAL 9.8 The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in … wordfence
41108c2c-99b2-4aff-8c06-bee0b6547a9a
< 3.9.7
CRITICAL 9.8 The Smart Manager For WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the ‘edited’ paramet… wordfence
41048058-1662-4ec1-81ac-6e8e42351e7e
< 12.3.1
CRITICAL 9.8 The Order Delivery Date for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can… wordfence
40a6d10e-5e68-4280-a3e2-0b93095bb4dd
< 3.4.8
CRITICAL 9.8 The Pearl - Corporate Business theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.4.8. This m… wordfence
40a6a810-1151-49e6-bed4-2b7a572ac015
< 2.4
CRITICAL 9.8 pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload… wordfence
40937e18-3828-4e36-8bc1-5b8eb4838c3b
< 1.2.1
CRITICAL 9.8 SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to… wordfence
407b8568-0b47-48d1-a006-2c42e7cfdec3 CRITICAL 9.8 The Right Now theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'up… wordfence
407a0bc3-2775-4a34-9817-924bf94a4f94 CRITICAL 9.8 The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the… wordfence
40765cfe-a60a-44dc-8cdb-f9c8e42654c3
< 9.1.1
CRITICAL 9.8 The BuddyPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘BP_Notifications_Notification::get… wordfence
40716c58-1075-492b-9323-13e7b831e206
< 3.5.19
CRITICAL 9.8 The WPFunnels plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.18 via de… wordfence
406c02e0-cebb-400a-b276-dc0b0bd9f1ad CRITICAL 9.8 The Workreap Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.4.… wordfence
40519181-540e-44d4-a9b7-6c8c321b1592
< 2.2.14.1
CRITICAL 9.8 The Kids Planet theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.14 via d… wordfence
403c881c-b687-4e7e-8e77-a55203cfde96
< 3.9
CRITICAL 9.8 The Chameleon theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'qq… wordfence
40010bbd-049f-44b0-9492-4126c4894656
< 1.8.0
CRITICAL 9.8 The Cooked Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… wordfence
40000879-a5ef-48f2-97e4-77d527259af0
< 1.2.6
CRITICAL 9.8 The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
3fddf96e-029c-4753-ba82-043ca64b78d3
< 7.10.1
CRITICAL 9.8 The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.1… wordfence
3f95f73c-2377-46b7-a96f-6014a5b012c3
< 2.4.4
CRITICAL 9.8 Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plu… wordfence
3f915fa1-38ca-4090-8f3f-3d8a1b0a2c4c CRITICAL 9.8 The MH Board plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.2.1. T… wordfence
← Prev 73 74 75 76 77 78 79 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top