🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 80 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
420580e1-b6cf-4fd7-87fd-e415b097f4c9 CRITICAL 9.8 The Davenport - Versatile Blog and Magazine WordPress Theme plugin for WordPress is vulnerable to Local File Inclusion i… — wordfence
41cfe1d7-2fab-413c-80e5-40d77133d229
< 11.31.0
CRITICAL 9.8 The Knowledge Base for Documentation, FAQs with AI Assistance plugin for WordPress is vulnerable to PHP Object Injection… — wordfence
41cf57ff-421d-4db2-894f-17f2c4d4b9ed
< 5.6.2
CRITICAL 9.8 The WooCommerce Payments plugin is vulnerable to authentication bypass via the determine_current_user_for_platform_check… — wordfence
41af6441-bc1d-4210-92f3-4c765fda6df9
< 1.9.13
CRITICAL 9.8 NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload — wordfence
41a61c0f-fffb-4810-b44a-74cbc1192ecd CRITICAL 9.8 The HTML5 AV Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… — wordfence
419a42eb-19ed-46a3-9da0-3fcd2c8e2527 CRITICAL 9.8 The Share Buttons – Social Media plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… — wordfence
41800ea9-1ace-42fc-9e7f-d760a126342b
< 1.7
CRITICAL 9.8 The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and incl… — wordfence
415c9658-bfb2-453b-a697-c63c08b0ca61
< 1.8.0
CRITICAL 9.8 The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Rem… — wordfence
414636bc-3fab-41f9-9d4b-17ca1ac8a3df
< 1.4.72
CRITICAL 9.8 The Motors plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.71. This mak… — wordfence
4124003c-4864-48f1-acba-9a613d9c99ae
< 5.4
CRITICAL 9.8 The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including,… — wordfence
4122a963-b8e2-448a-b268-3192613fa3df
< 4.1.4
CRITICAL 9.8 The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in … — wordfence
41108c2c-99b2-4aff-8c06-bee0b6547a9a
< 3.9.7
CRITICAL 9.8 The Smart Manager For WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the ‘edited’ paramet… — wordfence
41048058-1662-4ec1-81ac-6e8e42351e7e
< 12.3.1
CRITICAL 9.8 The Order Delivery Date for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can… — wordfence
40a6d10e-5e68-4280-a3e2-0b93095bb4dd
< 3.4.8
CRITICAL 9.8 The Pearl - Corporate Business theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.4.8. This m… — wordfence
40a6a810-1151-49e6-bed4-2b7a572ac015
< 2.4
CRITICAL 9.8 pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload… — wordfence
40937e18-3828-4e36-8bc1-5b8eb4838c3b
< 1.2.1
CRITICAL 9.8 SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to… — wordfence
407b8568-0b47-48d1-a006-2c42e7cfdec3 CRITICAL 9.8 The Right Now theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'up… — wordfence
407a0bc3-2775-4a34-9817-924bf94a4f94 CRITICAL 9.8 The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the… — wordfence
40765cfe-a60a-44dc-8cdb-f9c8e42654c3
< 9.1.1
CRITICAL 9.8 The BuddyPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘BP_Notifications_Notification::get… — wordfence
40716c58-1075-492b-9323-13e7b831e206
< 3.5.19
CRITICAL 9.8 The WPFunnels plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.18 via de… — wordfence
406c02e0-cebb-400a-b276-dc0b0bd9f1ad CRITICAL 9.8 The Workreap Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.4.… — wordfence
40519181-540e-44d4-a9b7-6c8c321b1592
< 2.2.14.1
CRITICAL 9.8 The Kids Planet theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.14 via d… — wordfence
403c881c-b687-4e7e-8e77-a55203cfde96
< 3.9
CRITICAL 9.8 The Chameleon theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'qq… — wordfence
40010bbd-049f-44b0-9492-4126c4894656
< 1.8.0
CRITICAL 9.8 The Cooked Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… — wordfence
40000879-a5ef-48f2-97e4-77d527259af0
< 1.2.6
CRITICAL 9.8 The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… — wordfence
← Prev 77 78 79 80 81 82 83 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top