πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 83 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3a61ddbc-9118-4cad-a639-7822606a3181
< 1.2.4
CRITICAL 9.8 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass i… — wordfence
3a57bbf9-bb53-4040-9c38-4798852a6fb4
< 1.8.2
CRITICAL 9.8 The Bit Assist plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 1.8.1. This… — wordfence
3a556e1e-6b7e-4967-9e13-8549939e964b CRITICAL 9.8 The PressGrid theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.1 via … — wordfence
3a325371-e531-4cd9-bc39-d1b8f40a728f CRITICAL 9.8 The Sixtees theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the uplo… — wordfence
3a03b32f-a5a4-4c1b-ad93-0833af6c302e
< 1.0.4.4
CRITICAL 9.8 The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to PHP Object Injection in versions … — wordfence
39ced195-63a7-4f50-a4eb-b43d6069f7e1
< 1.0.0
CRITICAL 9.8 Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery… — wordfence
3980df03-e19e-4b02-9b6a-9af7d8eaf0f3 CRITICAL 9.8 The Xin theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.8.1 via deserial… — wordfence
396a58d2-8357-4a8b-88a7-8c4917e27eb6
< 6.2.9
CRITICAL 9.8 The Hide My WP plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, but not i… — wordfence
3925311f-d40b-4f54-9b98-a709b53ed179
< 2.1.1
CRITICAL 9.8 The Bug Library plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … — wordfence
38bcb908-1e6e-44be-9cf5-72dcfa4c4a4e CRITICAL 9.8 Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote att… — wordfence
389c0b89-e408-4ad5-9723-a16b745771f0
< 1.9.13
CRITICAL 9.8 The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions… — wordfence
385f5f37-6be8-4736-91ca-0dd6f1d762a9
< 3.0.7
CRITICAL 9.8 The Clean Retina theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.6. This… — wordfence
385c01fc-bed8-4c12-b420-9aecf4857434 CRITICAL 9.8 The Surveys plugin for WordPress is vulnerable to blind SQL Injection via the β€˜$_REQUEST['action']’ parameter in ver… — wordfence
3852aef6-42e7-4b71-a1ba-dd41284fd07b
< 2.0.0
CRITICAL 9.8 The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… — wordfence
385235e0-be33-49c6-bcde-27f3cd936ddf CRITICAL 9.8 The Signup Page plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal… — wordfence
37fd0582-5baf-4ced-a798-dc0970e90a3e
< 1.2.11
CRITICAL 9.8 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin fo… — wordfence
37e1a755-7c17-4cb4-acca-9f26238230f3
< 5.1.3
CRITICAL 9.8 The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom… — wordfence
37c22521-68ef-4d15-9633-8fe1af493a52
< 3.41
CRITICAL 9.8 The IP Blacklist Cloud plugin for WordPress is vulnerable to SQL Injections via several parameters in versions before 3.… — wordfence
37a8642d-07f5-4b1b-8419-e30589089162
< 12.0.4
CRITICAL 9.8 The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida… — wordfence
37848512-fbdf-48cd-9d59-5bfb1bdbe73d
< 4.0.6
CRITICAL 9.8 The Tutor LMS plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.5. T… — wordfence
3755a06e-2c2e-4c88-95d7-2619bb84efab CRITICAL 9.8 The WP Cookies Enabler plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.… — wordfence
373b51f0-92ad-4c9e-87b9-96b4e57cc05d
< 1.4.5
CRITICAL 9.8 The Anthology Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via… — wordfence
3718690f-68f1-49cd-8193-b30887daabf2 CRITICAL 9.8 The Revo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.26. This makes … — wordfence
370fbe22-df48-4f64-ba7f-5ab98b908f58 CRITICAL 9.8 The Yvora theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload… — wordfence
36fb5b8d-1ea4-45c2-8639-b229efdb57db
< 1.1.3
CRITICAL 9.8 The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authoriza… — wordfence
← Prev 80 81 82 83 84 85 86 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top