πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 82 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2e88aa9e-6d1d-44ba-8d63-2f4d4161bc9e
< 3.4
CRITICAL 9.8 The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to time-based… wordfence
2e78cb46-7964-4ba5-b9bf-d47de865dbd2
< 6.3.2
CRITICAL 9.8 The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Privilege Escalation in a… wordfence
2e6c60bb-d7c9-4925-afbe-00ea847d1f0b CRITICAL 9.8 The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to Remote Code Execution… wordfence
2e24da0c-13d2-4a3d-b918-0d28e3341d88 CRITICAL 9.8 The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.… wordfence
2df89ab9-5cc2-46cb-99b2-bc864e960a35
< 2.4.3
CRITICAL 9.8 The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configu… wordfence
2df449b4-3f3b-4afc-b391-8d8d11710c07
< 2.1.47
CRITICAL 9.8 The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, … wordfence
2d6e9aea-6ccb-4c83-83bb-63c9c9f59005
< 3.4.12
CRITICAL 9.8 The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticate… wordfence
2d6cbfc8-1ced-4757-b090-39add17afc77
< 5.3.0
CRITICAL 9.8 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to mi… wordfence
2d64e1c6-1e25-4438-974d-b7da0979cc40
< 4.2.6.6
CRITICAL 9.8 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜term_i… wordfence
2d58322f-e24d-40fd-8dab-20752b386bb9 CRITICAL 9.8 The WP REST API FNS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includi… wordfence
2d35279d-299e-4ca2-8f84-165284e058c8
< 5.9.9.6
CRITICAL 9.8 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via… wordfence
2d29c30c-bb42-4ed0-a78d-eeea5b256275
< 1.71.0
CRITICAL 9.8 The ark-core plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.70.0. T… wordfence
2d23a2b9-8476-4564-a5de-5e6cfc38ce68
< 1.6.6
CRITICAL 9.8 The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.… wordfence
2d10f043-df2c-4e81-bd99-e478a2dca0cf CRITICAL 9.8 The WordPress Shout Box Widget plugin is vulnerable to generic SQL Injection via the 'class_qshout.php' file in versions… wordfence
2d048878-12ae-442a-921d-c02a4e1e3974
< 34.06
CRITICAL 9.8 Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to exec… wordfence
2ceba97c-8dfe-4195-87f7-5835efa1cd1f
< 1.4.0
CRITICAL 9.8 The Checkout Field Visibility for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up … wordfence
2cb40ada-03db-49ed-9f0d-84177238710b CRITICAL 9.8 The Support Ticket Management System for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all ver… wordfence
2cb252c9-fd84-439a-9e7f-05a6000912eb
< 1.1.8
CRITICAL 9.8 The Meta News theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.7. This ma… wordfence
2c9fa6f9-a549-4629-862f-f9a47b13aa59
< 3.11.9
CRITICAL 9.8 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… wordfence
2c8a2446-60c1-4641-9b5c-229327724333 CRITICAL 9.8 The Goodlayers Hostel plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.1.2… wordfence
2c7a0b51-6626-449f-95f5-74c4847909de
< 2.1.4.1
CRITICAL 9.8 The InPost Gallery Plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.4 vi… wordfence
2c5bb593-59b5-4760-8d54-14d7665c7e7f
< 6.03.01
CRITICAL 9.8 The Event Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.02… wordfence
2c4615d4-92b4-45d3-9fb7-66c9f5d6bdd2 CRITICAL 9.8 The GetShop ecommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3. … wordfence
2c1e6298-f243-49a5-b1b7-52bd6a6c8858
< 1.1
CRITICAL 9.8 The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulne… wordfence
2be770c7-7aa2-430b-981d-5d81fe068bef
< 1.3.33
CRITICAL 9.8 The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable… wordfence
← Prev 79 80 81 82 83 84 85 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top