πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 83 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2be3638e-3a0d-40e5-914e-9f20971abf9a CRITICAL 9.8 SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remo… wordfence
2bc8c04f-3764-473e-a216-7c5dc49abfa8 CRITICAL 9.8 SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote… wordfence
2b69f90a-1dd3-4184-aee3-9b0251b981cc
< 2.6.11
CRITICAL 9.8 The WP Migrate Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.… wordfence
2b6489f8-061d-4fbd-81f2-9f508dd0e7f8
< 3.3.1
CRITICAL 9.8 An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allo… wordfence
2b5a57d2-13bb-43d8-b495-e1d4d933b138
< 4.0.19
CRITICAL 9.8 The Eyewear prescription form plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p… wordfence
2b24693f-6b69-4dfb-a18c-e929db09d020
< 1.4.6
CRITICAL 9.8 The Pagelines Theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the pagelin… wordfence
2b0198c8-4be8-44e0-9728-d5d2aa376796
< 2.0
CRITICAL 9.8 The WooCommerce PPOM plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
2ae44bcb-6149-4661-8890-23c867e9a918
< 2.0.0
CRITICAL 9.8 The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc… wordfence
2ad674f7-aff6-432d-9c4c-95aebf8fcf6b
< 2.3.2
CRITICAL 9.8 SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute a… wordfence
2ad1af69-61e1-4453-866e-1ae71f614f30
< 2.1.7
CRITICAL 9.8 The Membership For WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… wordfence
2ab6e751-dc23-442f-b22e-ee41fd6651f6
< 2.0.4
CRITICAL 9.8 Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due… wordfence
2a6c5610-ed84-4d7d-a28f-d3807230e119
< 1.7.0
CRITICAL 9.8 The Web Directory Free plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.6.9 d… wordfence
2a4caee4-f4fa-45a6-8fe8-d5445bb097bf CRITICAL 9.8 The ListApp Mobile Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versio… wordfence
2a45fec7-cc69-4df6-98bb-ff70e5b6486c CRITICAL 9.8 The LMS Elementor Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1… wordfence
2a3e8c29-2e97-48f0-bf72-303857b51511
< 2.0.4
CRITICAL 9.8 The Enable CORS plugin contained a backdoor in all versions up to, and including, 2.0.3. This makes it possible for unau… wordfence
2a237492-0eb3-46fb-96dc-1959d8a87d1a CRITICAL 9.8 The Stacks Mobile App Builder – The most powerful Mobile Applications Drag and Drop builder plugin for WordPress is vu… wordfence
2a0671b1-1414-4315-8a2d-bd1aabe091a4
< 6.2.0
CRITICAL 9.8 The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and incl… wordfence
29e214fd-327b-45c4-a408-7ff56fd29876 CRITICAL 9.8 The Boat Rental Plugin for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… wordfence
29cbde71-772f-473c-9cad-0c5529b1aa97
< 2.10.3
CRITICAL 9.8 The Backpack Traveler theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.10.2… wordfence
29cbcbc9-a2a3-4518-a430-969ca76f9bda CRITICAL 9.8 The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including… wordfence
29ca151b-ef37-4f68-b0ea-b199ad6a4fce
< 1.1.14
CRITICAL 9.8 The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to Local File Inclusion in… wordfence
29adf3d2-b3a4-43f3-9aaa-bd2cf6cd115b CRITICAL 9.8 Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and event_form.php code do not sanitize input, this … wordfence
2988bb1f-0a32-4e9b-8096-46476879317b
< 15.6.9
CRITICAL 9.8 The Simple Business Directory Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 15.6.… wordfence
2971547d-39da-46f1-b62c-1918042ae654
< 3.4
CRITICAL 9.8 The Image News Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
2948d8f6-4b7b-49c3-a917-4306448416ff
< 2.6.4
CRITICAL 9.8 The Houzez Login Register plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2… wordfence
← Prev 80 81 82 83 84 85 86 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top