ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 81 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
31bcc1e1-08b6-4bbc-a28c-9c2d8feea819
< 1.3.4
CRITICAL 9.8 The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is be… wordfence
3184c304-52d3-4baa-b3c2-90957e1d8e79
< 13.1.0.6
CRITICAL 9.8 The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the… wordfence
31513f9e-6185-425b-9e7e-36f21f72d0a2
< 2.8.7
CRITICAL 9.8 The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection le… wordfence
3131eeeb-593d-443e-8641-7470bd1e556b CRITICAL 9.8 Mufeng's Hermit éŸ³ä¹æ’­æ”¾å™¨ plugin <= 3.1.6 is vulnerable to SQL injection. This allows unauthenticated attackers to… wordfence
311636d5-e990-4cdd-af1c-8b9610afa73e CRITICAL 9.8 The Team Rosters plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.8.2 via … wordfence
31052fe6-a0ae-4502-b2d2-dbc3b3bf672f
< 4.25.0
CRITICAL 9.8 The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrar… wordfence
30f8419c-c7b9-4c68-a845-26c0308d76f3
< 1.5.0
CRITICAL 9.8 The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection vi… wordfence
30ea46c1-bb29-49b8-b161-e61f13167ff4 CRITICAL 9.8 The Gallery From Files plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.… wordfence
30d592d0-323b-40d8-9f13-22041dbded31
< 2.0.14
CRITICAL 9.8 The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.p… wordfence
30aab1af-a78f-4bac-b3c5-30ea854ccef7
< 4.0.2
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versi… wordfence
308cd28a-a477-4bc6-a392-ad5a9eca1cb5
< 1.3.2
CRITICAL 9.8 The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1… wordfence
30532dc1-5d40-4585-abd2-c08ed0682d72
< 4.0.0
CRITICAL 9.8 An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain… wordfence
3045c9e5-4095-48e5-8d9d-16a091e69d54 CRITICAL 9.8 The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function … wordfence
2fb44c6e-520e-4a9f-9987-8b770feb710d
< 2.5.2
CRITICAL 9.8 The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includin… wordfence
2fa6d06d-7323-42d1-94ef-9dfda9c166c4
< 7.8.0
CRITICAL 9.8 The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerab… wordfence
2fa59f00-49f5-43ff-b3fe-0a62f52b0257
< 5.5.4
CRITICAL 9.8 The iControlWP plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.3. T… wordfence
2f8f6ade-84a2-4a42-9208-a74f5ebe19b3
< 1.8.3
CRITICAL 9.8 The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress mishandles sessions, which allows remote attackers to ob… wordfence
2f7e7b03-e709-44b6-8ff9-f2f0b3836629
< 1.3.8
CRITICAL 9.8 The AI Hub plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… wordfence
2f6822a9-94b2-47a8-9faa-5e1498e0dbde CRITICAL 9.8 The Background Image Cropper plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and incl… wordfence
2f52298b-344b-4561-b1bf-93bea95a3e53
< 1.0.29
CRITICAL 9.8 The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… wordfence
2f47a01d-b259-465e-bec1-9079987dc5a5
< 2.0.11
CRITICAL 9.8 The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on th… wordfence
2f0a7d6f-9b95-4052-bab3-85aca01f6ab7
< 1.1.11
CRITICAL 9.8 The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This… wordfence
2ef5e73e-a627-4e9c-9784-493ace5c8614
< 4.91.9
CRITICAL 9.8 The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execut… wordfence
2ef21a44-6d03-4197-b49c-d881f9831f46
< 8.9.1
CRITICAL 9.8 The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up… wordfence
2eeeb4b5-972b-471b-8f0f-a198640fc894
< 3.0
CRITICAL 9.8 The Memphis Documents Library plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… wordfence
← Prev 78 79 80 81 82 83 84 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top