πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 79 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3925311f-d40b-4f54-9b98-a709b53ed179
< 2.1.1
CRITICAL 9.8 The Bug Library plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … wordfence
38bcb908-1e6e-44be-9cf5-72dcfa4c4a4e CRITICAL 9.8 Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote att… wordfence
389c0b89-e408-4ad5-9723-a16b745771f0
< 1.9.13
CRITICAL 9.8 The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions… wordfence
385f5f37-6be8-4736-91ca-0dd6f1d762a9
< 3.0.7
CRITICAL 9.8 The Clean Retina theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.6. This… wordfence
385c01fc-bed8-4c12-b420-9aecf4857434 CRITICAL 9.8 The Surveys plugin for WordPress is vulnerable to blind SQL Injection via the β€˜$_REQUEST['action']’ parameter in ver… wordfence
3852aef6-42e7-4b71-a1ba-dd41284fd07b
< 2.0.0
CRITICAL 9.8 The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
385235e0-be33-49c6-bcde-27f3cd936ddf CRITICAL 9.8 The Signup Page plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal… wordfence
37fd0582-5baf-4ced-a798-dc0970e90a3e
< 1.2.11
CRITICAL 9.8 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin fo… wordfence
37e1a755-7c17-4cb4-acca-9f26238230f3
< 5.1.3
CRITICAL 9.8 The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom… wordfence
37c22521-68ef-4d15-9633-8fe1af493a52
< 3.41
CRITICAL 9.8 The IP Blacklist Cloud plugin for WordPress is vulnerable to SQL Injections via several parameters in versions before 3.… wordfence
37a8642d-07f5-4b1b-8419-e30589089162
< 12.0.4
CRITICAL 9.8 The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida… wordfence
3755a06e-2c2e-4c88-95d7-2619bb84efab CRITICAL 9.8 The WP Cookies Enabler plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.… wordfence
373b51f0-92ad-4c9e-87b9-96b4e57cc05d
< 1.4.5
CRITICAL 9.8 The Anthology Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via… wordfence
3718690f-68f1-49cd-8193-b30887daabf2 CRITICAL 9.8 The Revo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.26. This makes … wordfence
370fbe22-df48-4f64-ba7f-5ab98b908f58 CRITICAL 9.8 The Yvora theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload… wordfence
36fb5b8d-1ea4-45c2-8639-b229efdb57db
< 1.1.3
CRITICAL 9.8 The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authoriza… wordfence
36fa4540-68d9-474f-abfc-ad91af97a238
< 1.7.6
CRITICAL 9.8 The GiftXtore theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.5. This ma… wordfence
36a7b681-6059-46a4-82a8-addfb8f452cc CRITICAL 9.8 The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_… wordfence
36a01fa7-39a6-4d33-9c6e-1c76756f02cf CRITICAL 9.8 The HB AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
368a3911-1d29-4378-aa6e-8a6ed54bbe0f
< 2.0.4
CRITICAL 9.8 The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc… wordfence
364fe5b3-561e-4005-a589-c7c2b9e85b99
< 4.4.7
CRITICAL 9.8 The ChatBot plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.4.6 via deser… wordfence
361f3fec-7176-4a25-943b-44a44dd77784
< 14.6.10
CRITICAL 9.8 The cforms2 plugin before 14.6.10 for WordPress has SQL injection via several parameters. wordfence
35f59c05-8d1d-45b1-813f-65435e4aaed3 CRITICAL 9.8 The Nabz Image Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, v1.00 due t… wordfence
35b86488-8f68-4738-a9a8-76d0b7976165
< 2.0.47
CRITICAL 9.8 The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, … wordfence
35b74f5b-f088-4307-81ba-2c379754c4a2 CRITICAL 9.8 Vulnerability in wordpress plugin wordpress-gallery-transformation v1.0, SQL injection is in ./wordpress-gallery-transfo… wordfence
← Prev 76 77 78 79 80 81 82 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top