πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 84 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
36fa4540-68d9-474f-abfc-ad91af97a238
< 1.7.6
CRITICAL 9.8 The GiftXtore theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.5. This ma… — wordfence
36a7b681-6059-46a4-82a8-addfb8f452cc CRITICAL 9.8 The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_… — wordfence
36a01fa7-39a6-4d33-9c6e-1c76756f02cf CRITICAL 9.8 The HB AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… — wordfence
368a3911-1d29-4378-aa6e-8a6ed54bbe0f
< 2.0.4
CRITICAL 9.8 The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc… — wordfence
364fe5b3-561e-4005-a589-c7c2b9e85b99
< 4.4.7
CRITICAL 9.8 The ChatBot plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.4.6 via deser… — wordfence
3628032a-3121-45a7-8a78-cfcd8ba6af2f
< 2.8.23.4
CRITICAL 9.8 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorizatio… — wordfence
361f3fec-7176-4a25-943b-44a44dd77784
< 14.6.10
CRITICAL 9.8 The cforms2 plugin before 14.6.10 for WordPress has SQL injection via several parameters. — wordfence
35f59c05-8d1d-45b1-813f-65435e4aaed3 CRITICAL 9.8 The Nabz Image Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, v1.00 due t… — wordfence
35b86488-8f68-4738-a9a8-76d0b7976165
< 2.0.47
CRITICAL 9.8 The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, … — wordfence
35b74f5b-f088-4307-81ba-2c379754c4a2 CRITICAL 9.8 Vulnerability in wordpress plugin wordpress-gallery-transformation v1.0, SQL injection is in ./wordpress-gallery-transfo… — wordfence
35a7b5a1-b052-4390-8e08-f97aa9c16b29
< 3.2.7
CRITICAL 9.8 The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPres… — wordfence
359833dd-de3c-48ea-8eef-06588a590da2
< 3.2.2
CRITICAL 9.8 The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions … — wordfence
35806af6-bb63-41c8-a20b-f5e36d2aa515 CRITICAL 9.8 The WP Ultimate Email Marketer plugin 1.2.0 and possibly earlier for Wordpress does not properly restrict access to (1) … — wordfence
3511ba64-56a3-43d7-8ab8-c6e40e3b686e
< 1.3.8
CRITICAL 9.8 The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1… — wordfence
34fd42cb-3868-4b1c-bc56-575faf01e8f3
< 6.0.13
CRITICAL 9.8 The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. Th… — wordfence
34b52ca2-c05f-49b7-846f-a67136d7d379 CRITICAL 9.8 The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… — wordfence
346af237-0411-4cc4-9544-eab697385a2f
< 1.1.8
CRITICAL 9.8 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f… — wordfence
34612902-1a26-4759-bca6-b5aaffa25af4 CRITICAL 9.8 The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, an… — wordfence
345834f2-e95e-4ea1-b171-1c3f4aa17e0e CRITICAL 9.8 The WordPress Checkout plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … — wordfence
34439db4-1b66-4ccb-bf84-fddef6bc1f88
< 1.5.2
CRITICAL 9.8 The Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce plugin for WordPres… — wordfence
3417ec27-6abf-45c7-945f-6ef456ba1187 CRITICAL 9.8 The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, a… — wordfence
33df72a5-d2bc-4af5-b5bc-f26d7249d238 CRITICAL 9.8 The Think Responsive theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … — wordfence
339ab2b6-ca5e-41a8-ad32-9d2a271fb320 CRITICAL 9.8 The amerisale-re plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via th… — wordfence
33989611-8640-4c33-a34e-14f10cd7286d
< 3.8.1
CRITICAL 9.8 The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… — wordfence
33680429-8a52-412b-ab61-d261801319a0
< 1.1.2
CRITICAL 9.8 The simple-login-log plugin before 1.1.2 for WordPress has SQL injection via the 'orderby' parameter in the get_results … — wordfence
← Prev 81 82 83 84 85 86 87 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top