πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 85 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
336675c3-b397-42c5-85b0-5a38e1d7bc92 CRITICAL 9.8 The SoftMarket β€” Digital Marketplace plugin for WordPress is vulnerable to privilege escalation via account takeover i… — wordfence
3320c182-b1f9-4e06-92ea-0fa670557dd0 CRITICAL 9.8 The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up … — wordfence
32fe415d-f96d-4023-9faf-b83e7ff6acb1 CRITICAL 9.8 The Quick Count plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.00 via de… — wordfence
32e8224d-a653-48d7-a3f4-338fc0c1dc77
< 1.3.9.6
CRITICAL 9.8 The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… — wordfence
32d81267-f17c-4d53-bbc9-7b52683351e3 CRITICAL 9.8 The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request. — wordfence
32b6ccfe-a659-41e4-9cec-146f4f910071
< 1.4.5
CRITICAL 9.8 The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalatio… — wordfence
324fcf1b-a811-4750-bf48-87cb6570d51a CRITICAL 9.8 The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter. — wordfence
31f32e84-773e-492d-8f1a-5250e602f952 CRITICAL 9.8 The the-wound plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.0.1. Th… — wordfence
31e518a9-316b-40a4-ada7-317fb2c16766
< 2.2.7
CRITICAL 9.8 The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t… — wordfence
31d7c673-b625-4862-bc03-378ad663467c CRITICAL 9.8 Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS so… — wordfence
31cafa29-6040-4fb3-a929-a13b4c087ae0
< 1.1.16
CRITICAL 9.8 The Maia theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.15. This makes … — wordfence
31ca2de5-d63c-4ff8-9963-b96213d17cd0
< 3.4
CRITICAL 9.8 The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via… — wordfence
31bcc1e1-08b6-4bbc-a28c-9c2d8feea819
< 1.3.4
CRITICAL 9.8 The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is be… — wordfence
3184c304-52d3-4baa-b3c2-90957e1d8e79
< 13.1.0.6
CRITICAL 9.8 The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the… — wordfence
31513f9e-6185-425b-9e7e-36f21f72d0a2
< 2.8.7
CRITICAL 9.8 The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection le… — wordfence
3131eeeb-593d-443e-8641-7470bd1e556b CRITICAL 9.8 Mufeng's Hermit ιŸ³δΉζ’­ζ”Ύε™¨ plugin <= 3.1.6 is vulnerable to SQL injection. This allows unauthenticated attackers to… — wordfence
311636d5-e990-4cdd-af1c-8b9610afa73e CRITICAL 9.8 The Team Rosters plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.8.2 via … — wordfence
31052fe6-a0ae-4502-b2d2-dbc3b3bf672f
< 4.25.0
CRITICAL 9.8 The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrar… — wordfence
30f8419c-c7b9-4c68-a845-26c0308d76f3
< 1.5.0
CRITICAL 9.8 The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection vi… — wordfence
30ea46c1-bb29-49b8-b161-e61f13167ff4 CRITICAL 9.8 The Gallery From Files plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.… — wordfence
30d592d0-323b-40d8-9f13-22041dbded31
< 2.0.14
CRITICAL 9.8 The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.p… — wordfence
30cc4552-bd12-4211-bd06-637352ceb5df
< 1.3.9.9
CRITICAL 9.8 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Remote Code Execution in… — wordfence
30aab1af-a78f-4bac-b3c5-30ea854ccef7
< 4.0.2
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versi… — wordfence
308cd28a-a477-4bc6-a392-ad5a9eca1cb5
< 1.3.2
CRITICAL 9.8 The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1… — wordfence
30532dc1-5d40-4585-abd2-c08ed0682d72
< 4.0.0
CRITICAL 9.8 An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain… — wordfence
← Prev 82 83 84 85 86 87 88 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top