🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 77 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3f8397ff-35aa-445f-b370-d9fd0d1847e6
< 7.8.5
CRITICAL 9.8 The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to Remote Code Execution… wordfence
3f6870fa-e11b-4d59-9008-8b156417e93b
< 1.4
CRITICAL 9.8 The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘page_id’ parameter in versions up … wordfence
3f4806a3-643e-45b0-953f-6c0628359495
< 3.4.3.16
CRITICAL 9.8 The WP Shop plugin for WordPress is vulnerable to blind SQL Injection via the ‘wpshop_id’ parameter in versions up t… wordfence
3f21a356-193e-4eab-a8be-d88315421d03
< 1.5.1
CRITICAL 9.8 The flozen-theme theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … wordfence
3f202cc3-ab74-4abb-9eed-b4caf9fccb71
< 5.2.8
CRITICAL 9.8 The JoomSport plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.7 due to insuffi… wordfence
3ee1f412-7555-4dec-ba59-49412471a42f CRITICAL 9.8 The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including… wordfence
3ed30ebb-cb06-428c-a60e-676f36e75fa9 CRITICAL 9.8 The Woocommerce Tranzila Payment Gateway plugin for WordPress is vulnerable to PHP Object Injection in all versions up t… wordfence
3ed280ba-d7e5-4637-ab84-93dc82c009d8 CRITICAL 9.8 The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which… wordfence
3ea52e59-d81c-4a3f-953e-34f8214c01d8 CRITICAL 9.8 The Ads Box plugin for WordPress is vulnerable to generic SQL Injection via the iframe_ampl.php file in versions up to, … wordfence
3e744c77-efa2-4910-af18-56aa15424412
< 4.2
CRITICAL 9.8 The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication. wordfence
3e650516-49eb-4475-8faa-76ca123d531f
< 1.2.0
CRITICAL 9.8 A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 1.2.0 for WordPr… wordfence
3e44b1e6-7342-4788-af80-aac6319f5246 CRITICAL 9.8 The Easy Digital Downloads – Recent Purchases plugin for WordPress is vulnerable to Remote File Inclusion in all versi… wordfence
3def97d8-4f25-4a67-bdce-7664a5c318bc
< 1.7
CRITICAL 9.8 The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to arbitrary file uploads in all vers… wordfence
3de27b2e-2196-4b8e-816c-729462a172d0
< 4.3
CRITICAL 9.8 The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and … wordfence
3ddde57f-4fb1-42c9-9280-de589320e191
< 4.2.7
CRITICAL 9.8 The Gift Cards For WooCommerce Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type… wordfence
3dd08e56-0425-4711-87f1-39625f0ffae2
< 2.2.3
CRITICAL 9.8 The Mobile Assistant Connector plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.2… wordfence
3d996df9-3d61-4b2b-8d74-4faa7c5a151a
< 1.4b5
CRITICAL 9.8 PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.2.1 and earlier plugin fo… wordfence
3d7b4428-99ac-4f84-8595-941124121eb2 CRITICAL 9.8 The WP Forum plugin for WordPress is vulnerable to blind SQL Injection via the ‘topic’ parameter in versions up to, … wordfence
3d71404e-0db8-485b-a626-5e0df2076c05
< 1.2.8
CRITICAL 9.8 The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
3d5dfccd-74ab-4de9-8ea6-58908865086d
< 1.0.4
CRITICAL 9.8 The Revamp CRM for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includi… wordfence
3d5256ea-61ba-4b2d-90d6-714176bc19aa
< 1.5.0
CRITICAL 9.8 A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitat… wordfence
3d438d11-df72-431e-8956-6a7b316a6dc3 CRITICAL 9.8 The sintic_gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via … wordfence
3d0e1007-396b-4b57-be16-6fa7fe87d92c CRITICAL 9.8 The Podiant plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1. This m… wordfence
3ce95a04-11bd-488e-ad25-1b661e083eb2
< 1.0.4
CRITICAL 9.8 The Case Theme User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.… wordfence
3cd81614-6f09-44ae-937a-694364ae2aba CRITICAL 9.8 The SUMO Reward Points plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 30.7… wordfence
← Prev 74 75 76 77 78 79 80 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top