πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 84 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2945ab15-e211-4a11-954a-002d0fd2a04d
< 1.61.1
CRITICAL 9.8 The Ogami theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.53. This makes i… wordfence
2927aa13-b012-41eb-93bd-38a4e5fc5455
< 3.19
CRITICAL 9.8 The TicketBAI Facturas para WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficien… wordfence
290e7b9d-23b6-47bb-9169-d2f9922b6492 CRITICAL 9.8 The Fami Sales Popup plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0.… wordfence
28cb96a9-12bd-4d9c-ac53-72e81d11b0b6
< 3.0.96
CRITICAL 9.8 The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier… wordfence
2882d9dd-0c73-4c9a-99cb-d10900503103 CRITICAL 9.8 The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. Th… wordfence
28713983-86ef-45d1-9258-d1a4feedcadd
< 4.08.253
CRITICAL 9.8 The WebinarIgnition – Live, Automated & Evergreen Webinar System also for WooCommerce plugin for WordPress is vulnerab… wordfence
284eafb9-94bc-4478-abff-f7dafd510a1d
< 4.1.3
CRITICAL 9.8 The Simple Membership plugin for WordPress is vulnerable to membership related privilege escalation in versions up to, a… wordfence
283b10e6-61ae-4e1d-be7b-a63aece6ffda
< 4.2.23
CRITICAL 9.8 The Etoile Ultimate Product Catalog plugin 4.2.22 for WordPress has SQL injection with these wp-admin/admin-ajax.php POS… wordfence
282a26e8-4848-4e40-bfe5-fe2ba40f198e
< 1.0.34
CRITICAL 9.8 Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow rem… wordfence
27f90d97-c62f-4591-ba26-8d204d567687
< 2.5.0
CRITICAL 9.8 The Avantage theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4.9 via deser… wordfence
27bb60c1-43fa-4a18-b9ca-059535b0d5b6
< 1.1.20
CRITICAL 9.8 The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in al… wordfence
2742cc47-8e3d-4fe4-b653-7310a4156a84
< 1.3.1
CRITICAL 9.8 The aDirectory – Directory Listing WordPress Plugin plugin for WordPress is vulnerable to arbitrary file uploads due t… wordfence
271b151c-5646-4206-a7db-739ac36a9fdd CRITICAL 9.8 The 1-Click Login: Passwordless Authentication plugin for WordPress is vulnerable to authentication bypass in version 1.… wordfence
271a35fb-56b7-4d6b-bccc-fea1227d0913 CRITICAL 9.8 The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… wordfence
2710b445-4281-4055-be37-56902ae1d1b6
< 2.0.66.1
CRITICAL 9.8 The Yozi theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.63. This makes … wordfence
26f4e785-724b-41d3-b479-cb0150e70f9e CRITICAL 9.8 The Advanced Booking Calendar for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.1 due t… wordfence
26d83a9d-3e51-450e-b3cb-7c53a4bcba60 CRITICAL 9.8 The PICA Photo Gallery plugin for WordPress is vulnerable to SQL Injection via the β€˜aid’ parameter in versions up to… wordfence
2693ae37-790d-4b18-a9ec-054c8c27b8bc
< 3.4.4
CRITICAL 9.8 The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3… wordfence
268b77b9-af1d-41c8-9f24-99b60eb04cc4
< 3.4.3
CRITICAL 9.8 The ConvertPlug plugin for WordPress is vulnerable to Unauthenticated Administrator Creation in versions up to, and incl… wordfence
2685a2b4-aba3-425b-af0d-06f7693ab3d7
< 1.1.5
CRITICAL 9.8 The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due t… wordfence
2655ec9f-471f-48e7-8e1c-a428ef3b46ee CRITICAL 9.8 Unrestricted file upload vulnerability in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote att… wordfence
2652a7fc-b610-40f1-8b76-2129f59390ec
< 3.8.0
CRITICAL 9.8 The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in … wordfence
2637e273-a308-4033-be5a-2f778f8df282
< 1.2.2
CRITICAL 9.8 The Create Block Theme plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization via the… wordfence
262e3bb3-bc83-4d0b-8056-9f94ec141b8f
< 6.05
CRITICAL 9.8 The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '… wordfence
26153183-45f1-4694-94ec-f547f1b99089 CRITICAL 9.8 The Recently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1 via deseri… wordfence
← Prev 81 82 83 84 85 86 87 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top