πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 78 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3ccd7300-f22a-405a-8087-9c750cb187a5
< 2.0.1
CRITICAL 9.8 The InBoundio Marketing plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
3cb03d81-ac33-487b-bf4d-927e8104866e
< 2.8.3
CRITICAL 9.8 The Category Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including… wordfence
3ca33a74-6deb-4b6e-b326-31a4f48b101f CRITICAL 9.8 The FLAP - Business WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and inc… wordfence
3c601919-4026-4452-9034-b4381fe7c960
< 2.8.3.1
CRITICAL 9.8 The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable … wordfence
3c545c65-19c0-4566-9db4-4fa2fef3d59a CRITICAL 9.8 The Job Board Manager for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, an… wordfence
3c1f625e-4456-45e4-8a7f-809b22edb66b
< 1.7.2
CRITICAL 9.8 The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads … wordfence
3c0bd6ee-da23-4e1e-9dbc-1ee4a111f7f8
< 1.2
CRITICAL 9.8 The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal. wordfence
3bfc18fa-905c-408f-bbb4-ce207c322298
< 6.1.5
CRITICAL 9.8 The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before usi… wordfence
3bbe4570-8aa2-4d95-8822-4e67cf352fdb
< 1.0.7
CRITICAL 9.8 The Majestic Support plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.6.… wordfence
3bbbf5be-5c0a-4514-88ac-003083c0bba3
< 10.3
CRITICAL 9.8 The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… wordfence
3bb4a8ba-33f1-4183-be76-72f6a99fc1fa
< 12.8
CRITICAL 9.8 The Indeed Membership Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includin… wordfence
3ba7f9cb-2615-4c9e-a4d8-648860afd7a4
< 1.1.2
CRITICAL 9.8 The Charity Zone theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … wordfence
3b93c33c-4ab1-48a2-b84d-3cb38ccea829
< 2.4.3
CRITICAL 9.8 The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is… wordfence
3b71c90d-addc-4cbb-9d6c-9d0a3471ac1f
< 1.3.01
CRITICAL 9.8 The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerabl… wordfence
3b5630bd-5bce-4226-959f-5e81ae69b799
< 6.0.7
CRITICAL 9.8 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escala… wordfence
3b4e92a1-cac7-445d-a47c-52058e652c09 CRITICAL 9.8 The WordPress RokBox plugin is vulnerable to arbitrary file uploads due to missing file type validation in the 'src' par… wordfence
3b2b5da9-a421-48fb-9e91-8ef495cbdc37
< 1.44
CRITICAL 9.8 PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, … wordfence
3afcc49d-8662-4f63-9e6f-fcf76932effc
< 1.2.7
CRITICAL 9.8 The JobBoard Job listing plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… wordfence
3a9f775f-4b82-449c-a5c3-d881b983d2c4
< 5.71
CRITICAL 9.8 The DeBounce Email Validator plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… wordfence
3a556e1e-6b7e-4967-9e13-8549939e964b CRITICAL 9.8 The PressGrid theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.1 via … wordfence
3a325371-e531-4cd9-bc39-d1b8f40a728f CRITICAL 9.8 The Sixtees theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the uplo… wordfence
3a03b32f-a5a4-4c1b-ad93-0833af6c302e
< 1.0.4.4
CRITICAL 9.8 The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to PHP Object Injection in versions … wordfence
39ced195-63a7-4f50-a4eb-b43d6069f7e1
< 1.0.0
CRITICAL 9.8 Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery… wordfence
3980df03-e19e-4b02-9b6a-9af7d8eaf0f3 CRITICAL 9.8 The Xin theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.8.1 via deserial… wordfence
396a58d2-8357-4a8b-88a7-8c4917e27eb6
< 6.2.9
CRITICAL 9.8 The Hide My WP plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, but not i… wordfence
← Prev 75 76 77 78 79 80 81 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top