πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 8 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ffd9cbd1-f8a9-401e-8cdd-1ff16f438b4a
< 4.1.2
CRITICAL 9.8 The User Registration & Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and inc… wordfence
ffd592e6-2ac4-4af4-bfc0-d4f834157d71
< 2.6.3
CRITICAL 9.8 The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… wordfence
ffa0d1ff-a1df-4a90-bfe5-3f4c8a7942c6
< 1.0.11
CRITICAL 9.8 The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in … wordfence
ff87e9e0-d8b1-47d3-92d6-48e6b00ac1a0 CRITICAL 9.8 The Real Time Validation for Gravity Forms plugin for WordPress is vulnerable to Local File Inclusion in versions up to,… wordfence
ff6fc652-dcf8-4ff6-b8d8-cb9fad5b34bd
< 2.2
CRITICAL 9.8 The 3D Flick Slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
ff5755dc-2262-47f6-ac3a-6bca9529d088
< 1.7
CRITICAL 9.8 The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, a… wordfence
ff4b47d8-28c1-4706-91d9-0285f419147e
< 3.7.40
CRITICAL 9.8 WordPress Core is vulnerable to SQL Injection in versions up to 6.0.3. This is due to insufficient escaping on where β€œ… wordfence
ff4243e9-cf72-40d5-bc7d-204426024a1d CRITICAL 9.8 The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to… wordfence
ff1f303f-17fc-4006-b21b-5846216995da
< 92.0.0
CRITICAL 9.8 The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f… wordfence
fea82b46-cb23-4603-8e50-565cc65db857
< 1.5.8
CRITICAL 9.8 The AI Copilot – Content Generator plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a… wordfence
fea6ddd5-f168-471c-99eb-efc46d1bfeb9
< 1.4.13
CRITICAL 9.8 The wpForo Forum plugin for WordPress is vulnerable to Blind SQL Injection via the β€˜wpfo’ parameter in versions up t… wordfence
fe887475-f7e8-4fda-a793-bc6f37b70f3e
< 1.9.15
CRITICAL 9.8 The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.… wordfence
fe8723a7-bbb1-41a0-b222-3cf4eb44cd64
< 1.0.3
CRITICAL 9.8 The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2 … wordfence
fe17abd8-9ee2-4b9c-a30b-68d95e341722
< 3.1.4
CRITICAL 9.8 The ReFlex Gallery Β» WordPress Photo Gallery for WordPress is vulnerable to arbitrary file uploads due to missing file … wordfence
fdc2de78-5601-461f-b2f0-c80b592ccb1b
< 1.22.22
CRITICAL 9.8 The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… wordfence
fdc2a31f-19c2-4474-a3b0-16ded1912ddd
< 5.6.4
CRITICAL 9.8 The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection. wordfence
fdba935b-4c78-48e2-ae32-f68748f6df97 CRITICAL 9.8 The TheCartPress eCommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up t… wordfence
fd978ac0-42f2-4746-9430-37458375b588
< 2.0.9.9
CRITICAL 9.8 The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to Sensitive Information Exposure in a… wordfence
fd8e6b8a-0161-4bf7-b480-77258337e9b9
< 3.4.1
CRITICAL 9.8 The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files. wordfence
fd50ac2c-3049-4a44-b7f8-a5f87c42555c
< 1.3.1
CRITICAL 9.8 The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account … wordfence
fd3b4c44-d47a-45de-bcb2-0820e475b331
< 24.0.4
CRITICAL 9.8 The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Soc… wordfence
fcf4bf2c-2f65-415b-bbf3-d7c01d88c8f8
< 6.2.3
CRITICAL 9.8 The LoginPress Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.2.… wordfence
fced0686-f56d-4163-80fd-362ee652d148
< 3.6.8
CRITICAL 9.8 The WP Timeline – Vertical and Horizontal timeline plugin plugin for WordPress is vulnerable to Local File Inclusion i… wordfence
fccfe581-16aa-4a6e-a6aa-60c05e4d26cb
< 3.2.0
CRITICAL 9.8 The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders i… wordfence
fcc78fa6-a5f0-4f29-ae19-8e783698b19e
< 1.9.5
CRITICAL 9.8 The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to… wordfence
← Prev 5 6 7 8 9 10 11 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top