๐Ÿ›ก๏ธ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 77 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
49e133c9-5d3b-4a2a-8385-e2db44baa217
< 1.5.4
CRITICAL 9.8 The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and excluding, 1.5.4. Thi… — wordfence
49cac6e5-c224-49f3-9f3d-07b07fc5e4cc
< 3.15.2
CRITICAL 9.8 The User Profile Builder โ€“ Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… — wordfence
49ca1e15-b015-4e9e-bb79-be3968689609 CRITICAL 9.8 The Userpro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.1.9. This mak… — wordfence
49c3be3f-60b3-4b83-9683-a08e8e1cf9e9
< 4.16.7.2
CRITICAL 9.8 The GiveWP โ€“ Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… — wordfence
49ae7971-7bdf-4369-b04b-fb48ea5b9518
< 2.6.1
CRITICAL 9.8 The ็ฎ€ๆ•ฐ้‡‡้›†ๅ™จ (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… — wordfence
49a34919-94bc-4369-a0c1-e34d7563116d
< 5.4.6
CRITICAL 9.8 The User Registration PRO โ€“ Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPre… — wordfence
496b1c3a-7fbb-4088-9936-6b023718946d
< 3.4.22
CRITICAL 9.8 The My Calendar plugin for WordPress is vulnerable to [blind|generic|time-based] SQL Injection via the 'from' and 'to' p… — wordfence
494ef738-c900-4d00-8739-3b261586d4ff CRITICAL 9.8 The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0.… — wordfence
494c780d-5441-407d-8947-e56d7cac32d6
< 3.9.8
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'store_id' parameter in… — wordfence
491f44fc-712c-4f67-b5c2-a7396941afc1
< 3.6.1
CRITICAL 9.8 The Post SMTP โ€“ Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable … — wordfence
48f7ad3b-608b-4802-b7ab-fad4c449cc62
< 2.6.1.4
CRITICAL 9.8 The SP Projects & Document Manager plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and i… — wordfence
48e7acf2-61d4-4762-8657-0701910ce69b
< 0.0.9.19
CRITICAL 9.8 The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of … — wordfence
48add930-a350-4828-84a0-e1207a9b239b
< 3.26
CRITICAL 9.8 The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to Remote Code Execution in all … — wordfence
48950965-f7da-42af-9f9a-4bf7fd33be45
< 7.0
CRITICAL 9.8 The AR for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … — wordfence
48949329-8918-4d37-9f3a-1005e99d7e4d
< 1.7.0
CRITICAL 9.8 The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before u… — wordfence
4893d7a7-6e37-4b58-b7ae-53feb0c85ff5 CRITICAL 9.8 The Uploadify plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'p… — wordfence
486c1c7c-5a66-42d3-85b0-13ce52a16ed1
< 45.16.1
CRITICAL 9.8 The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an… — wordfence
4848292a-0378-4e0c-a95f-3232c5ce9b9f CRITICAL 9.8 The The Business theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.1 via d… — wordfence
4830fb09-c138-4316-bdde-c233d58b0d91
< 5.1.9
CRITICAL 9.8 The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthenticated account … — wordfence
481c738e-d544-4587-8632-e85a7ddd8b14
< 3.6.17
CRITICAL 9.8 The WatchTowerHQ plugin for WordPress is vulnerable to a type juggling issue in versions up to, and including, 3.6.16. T… — wordfence
4770441f-5d8b-4edb-93e3-d2d73f145d26
< 2.0.9
CRITICAL 9.8 SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allow… — wordfence
476df648-5024-42af-9bbd-a5a98e79453f
< 1.8.5
CRITICAL 9.8 The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… — wordfence
4750b57e-7d8d-49d7-bbbf-46483eb97bd9 CRITICAL 9.8 The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This … — wordfence
474ad5a5-6384-41cb-a60b-e25477d48ad7 CRITICAL 9.8 upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via… — wordfence
47337bc1-fa3d-470c-9524-859295261017 CRITICAL 9.8 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, … — wordfence
← Prev 74 75 76 77 78 79 80 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top