πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 85 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
26140315-04c7-4056-a570-865cd4ffe85e
< 7.0.2
CRITICAL 9.8 The Quiz and Survey Master plugin for WordPress is vulnerable to arbitrary file uploads due to missing filename sanitiza… wordfence
2597724a-9a39-4e46-b153-f42366f833ba
< 1.5.6.1
CRITICAL 9.8 All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to … wordfence
25971f3f-4816-416c-9de9-feb6326fe948
< 6.5
CRITICAL 9.8 The Super Store Finder plugin in versions up to, and including 6.4 and the Super Interactive Maps plugin in versions up … wordfence
259158f0-390a-458f-9d8e-262006c4c18d
< 1.0.7
CRITICAL 9.8 The Really Simple Guest Post plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… wordfence
256c4984-eee8-4ed0-ba34-e022822d6387 CRITICAL 9.8 The Private Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.1… wordfence
2565852f-43df-41b1-949e-6c02a8946407
< 3.0.0
CRITICAL 9.8 The Sitepact's Contact Form 7 Extension For Klaviyo plugin for WordPress is vulnerable to SQL Injection parameter in ver… wordfence
25627b5c-958c-45ad-8450-8dfccdfdac31 CRITICAL 9.8 The Radykal Fancy Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
2513a199-30a8-45a9-80b3-1f6e51534c88 CRITICAL 9.8 The Nightlife Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the up… wordfence
24f31bbf-883f-4903-847a-7bfc3e45654c CRITICAL 9.8 The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and im… wordfence
24e8d1a4-9853-4f60-a371-7fdbe86d554b
< 12.4
CRITICAL 9.8 The tagDiv Cloud Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
24d081e3-4291-427c-bf2c-726d93aa00ac
< 1.4
CRITICAL 9.8 The filedownload plugin for WordPress is vulnerable to blind SQL Injection in versions before 1.4 due to insufficient es… wordfence
24c9a333-e60e-481b-ba27-65094f4f8d39
< 5.0.7
CRITICAL 9.8 The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads … wordfence
24a88f20-ddc4-4544-ac18-ed538ecfa1c7 CRITICAL 9.8 Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1 in csv2wpecCoupon_FileUpload.php file. wordfence
2491d502-8087-4e95-b047-a3b196322d94
< 4.7.4
CRITICAL 9.8 The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user inp… wordfence
2489e649-27f7-4ca0-8655-0957016fa89a CRITICAL 9.8 The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to ins… wordfence
247ee5bf-1e77-4461-b9f7-28b051b78af7 CRITICAL 9.8 The Real Estate Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.3… wordfence
24517dc6-4995-48ee-9b02-5c7c29d359f6
< 3.05.1
CRITICAL 9.8 The Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin fo… wordfence
2450277e-589d-4153-bd3f-ffed1a8b4340 CRITICAL 9.8 The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/downl… wordfence
244b6773-8983-4435-8d1c-240bcc54e061 CRITICAL 9.8 The Lis Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.2.1… wordfence
240cc19a-9bae-4e69-a16f-46901daaa945
< 3.0.1
CRITICAL 9.8 The Brandfolder – Digital Asset Management Simplified. plugin for WordPress is vulnerable to Local and Remote File Inc… wordfence
24092cd1-cf89-49c1-a607-4d5d06d0c804 CRITICAL 9.8 The IP Loc8 plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1 via deseria… wordfence
23fbb011-cf60-4c75-ac68-b5d0dfa3c356
< 1.6.7
CRITICAL 9.8 Server-Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter. wordfence
23da892a-62c1-4c4b-8b86-4b55018c309b CRITICAL 9.8 The WPSPX plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.2. This m… wordfence
23c99d3c-5ee5-4793-92a4-f49bf345c634 CRITICAL 9.8 The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Remote C… wordfence
23aa8a2f-9238-4d93-b2d2-de7838ccb156
< 1.5.5
CRITICAL 9.8 SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5. wordfence
← Prev 82 83 84 85 86 87 88 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top