πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 80 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
35a7b5a1-b052-4390-8e08-f97aa9c16b29
< 3.2.7
CRITICAL 9.8 The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPres… wordfence
359833dd-de3c-48ea-8eef-06588a590da2
< 3.2.2
CRITICAL 9.8 The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions … wordfence
35806af6-bb63-41c8-a20b-f5e36d2aa515 CRITICAL 9.8 The WP Ultimate Email Marketer plugin 1.2.0 and possibly earlier for Wordpress does not properly restrict access to (1) … wordfence
3511ba64-56a3-43d7-8ab8-c6e40e3b686e
< 1.3.8
CRITICAL 9.8 The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1… wordfence
34fd42cb-3868-4b1c-bc56-575faf01e8f3
< 6.0.13
CRITICAL 9.8 The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. Th… wordfence
34b52ca2-c05f-49b7-846f-a67136d7d379 CRITICAL 9.8 The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… wordfence
346af237-0411-4cc4-9544-eab697385a2f
< 1.1.8
CRITICAL 9.8 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f… wordfence
34612902-1a26-4759-bca6-b5aaffa25af4 CRITICAL 9.8 The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, an… wordfence
345834f2-e95e-4ea1-b171-1c3f4aa17e0e CRITICAL 9.8 The WordPress Checkout plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
34439db4-1b66-4ccb-bf84-fddef6bc1f88
< 1.5.2
CRITICAL 9.8 The Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce plugin for WordPres… wordfence
33df72a5-d2bc-4af5-b5bc-f26d7249d238 CRITICAL 9.8 The Think Responsive theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
339ab2b6-ca5e-41a8-ad32-9d2a271fb320 CRITICAL 9.8 The amerisale-re plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via th… wordfence
33989611-8640-4c33-a34e-14f10cd7286d
< 3.8.1
CRITICAL 9.8 The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… wordfence
33680429-8a52-412b-ab61-d261801319a0
< 1.1.2
CRITICAL 9.8 The simple-login-log plugin before 1.1.2 for WordPress has SQL injection via the 'orderby' parameter in the get_results … wordfence
3320c182-b1f9-4e06-92ea-0fa670557dd0 CRITICAL 9.8 The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up … wordfence
32fe415d-f96d-4023-9faf-b83e7ff6acb1 CRITICAL 9.8 The Quick Count plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.00 via de… wordfence
32e8224d-a653-48d7-a3f4-338fc0c1dc77
< 1.3.9.6
CRITICAL 9.8 The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
32d81267-f17c-4d53-bbc9-7b52683351e3 CRITICAL 9.8 The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request. wordfence
32b6ccfe-a659-41e4-9cec-146f4f910071
< 1.4.5
CRITICAL 9.8 The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalatio… wordfence
324fcf1b-a811-4750-bf48-87cb6570d51a CRITICAL 9.8 The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter. wordfence
31f32e84-773e-492d-8f1a-5250e602f952 CRITICAL 9.8 The the-wound plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.0.1. Th… wordfence
31e518a9-316b-40a4-ada7-317fb2c16766
< 2.2.7
CRITICAL 9.8 The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t… wordfence
31d7c673-b625-4862-bc03-378ad663467c CRITICAL 9.8 Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS so… wordfence
31cafa29-6040-4fb3-a929-a13b4c087ae0
< 1.1.16
CRITICAL 9.8 The Maia theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.15. This makes … wordfence
31ca2de5-d63c-4ff8-9963-b96213d17cd0
< 3.4
CRITICAL 9.8 The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via… wordfence
← Prev 77 78 79 80 81 82 83 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top