🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 81 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3fddf96e-029c-4753-ba82-043ca64b78d3
< 7.10.1
CRITICAL 9.8 The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.1… — wordfence
3f95f73c-2377-46b7-a96f-6014a5b012c3
< 2.4.4
CRITICAL 9.8 Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plu… — wordfence
3f915fa1-38ca-4090-8f3f-3d8a1b0a2c4c CRITICAL 9.8 The MH Board plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.2.1. T… — wordfence
3f8397ff-35aa-445f-b370-d9fd0d1847e6
< 7.8.5
CRITICAL 9.8 The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to Remote Code Execution… — wordfence
3f6870fa-e11b-4d59-9008-8b156417e93b
< 1.4
CRITICAL 9.8 The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘page_id’ parameter in versions up … — wordfence
3f4806a3-643e-45b0-953f-6c0628359495
< 3.4.3.16
CRITICAL 9.8 The WP Shop plugin for WordPress is vulnerable to blind SQL Injection via the ‘wpshop_id’ parameter in versions up t… — wordfence
3f21a356-193e-4eab-a8be-d88315421d03
< 1.5.1
CRITICAL 9.8 The flozen-theme theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … — wordfence
3f211911-b8e1-4ee2-ad4a-189c58fdbe8d
< 3.15.2
CRITICAL 9.8 The Authorizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.15.1. … — wordfence
3f202cc3-ab74-4abb-9eed-b4caf9fccb71
< 5.2.8
CRITICAL 9.8 The JoomSport plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.7 due to insuffi… — wordfence
3ee1f412-7555-4dec-ba59-49412471a42f CRITICAL 9.8 The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including… — wordfence
3ed30ebb-cb06-428c-a60e-676f36e75fa9 CRITICAL 9.8 The Woocommerce Tranzila Payment Gateway plugin for WordPress is vulnerable to PHP Object Injection in all versions up t… — wordfence
3ed280ba-d7e5-4637-ab84-93dc82c009d8 CRITICAL 9.8 The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which… — wordfence
3ea52e59-d81c-4a3f-953e-34f8214c01d8 CRITICAL 9.8 The Ads Box plugin for WordPress is vulnerable to generic SQL Injection via the iframe_ampl.php file in versions up to, … — wordfence
3e744c77-efa2-4910-af18-56aa15424412
< 4.2
CRITICAL 9.8 The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication. — wordfence
3e650516-49eb-4475-8faa-76ca123d531f
< 1.2.0
CRITICAL 9.8 A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 1.2.0 for WordPr… — wordfence
3e44b1e6-7342-4788-af80-aac6319f5246 CRITICAL 9.8 The Easy Digital Downloads – Recent Purchases plugin for WordPress is vulnerable to Remote File Inclusion in all versi… — wordfence
3def97d8-4f25-4a67-bdce-7664a5c318bc
< 1.7
CRITICAL 9.8 The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to arbitrary file uploads in all vers… — wordfence
3de27b2e-2196-4b8e-816c-729462a172d0
< 4.3
CRITICAL 9.8 The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and … — wordfence
3ddde57f-4fb1-42c9-9280-de589320e191
< 4.2.7
CRITICAL 9.8 The Gift Cards For WooCommerce Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type… — wordfence
3dd08e56-0425-4711-87f1-39625f0ffae2
< 2.2.3
CRITICAL 9.8 The Mobile Assistant Connector plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.2… — wordfence
3d996df9-3d61-4b2b-8d74-4faa7c5a151a
< 1.4b5
CRITICAL 9.8 PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.2.1 and earlier plugin fo… — wordfence
3d7b4428-99ac-4f84-8595-941124121eb2 CRITICAL 9.8 The WP Forum plugin for WordPress is vulnerable to blind SQL Injection via the ‘topic’ parameter in versions up to, … — wordfence
3d71404e-0db8-485b-a626-5e0df2076c05
< 1.2.8
CRITICAL 9.8 The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… — wordfence
3d5dfccd-74ab-4de9-8ea6-58908865086d
< 1.0.4
CRITICAL 9.8 The Revamp CRM for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includi… — wordfence
3d5256ea-61ba-4b2d-90d6-714176bc19aa
< 1.5.0
CRITICAL 9.8 A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitat… — wordfence
← Prev 78 79 80 81 82 83 84 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top