πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 86 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3045c9e5-4095-48e5-8d9d-16a091e69d54
< 1.3
CRITICAL 9.8 The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function … — wordfence
2fb44c6e-520e-4a9f-9987-8b770feb710d
< 2.5.2
CRITICAL 9.8 The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includin… — wordfence
2fa6d06d-7323-42d1-94ef-9dfda9c166c4
< 7.8.0
CRITICAL 9.8 The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerab… — wordfence
2fa59f00-49f5-43ff-b3fe-0a62f52b0257
< 5.5.4
CRITICAL 9.8 The iControlWP plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.3. T… — wordfence
2f8f6ade-84a2-4a42-9208-a74f5ebe19b3
< 1.8.3
CRITICAL 9.8 The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress mishandles sessions, which allows remote attackers to ob… — wordfence
2f7e7b03-e709-44b6-8ff9-f2f0b3836629
< 1.3.8
CRITICAL 9.8 The AI Hub plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… — wordfence
2f6822a9-94b2-47a8-9faa-5e1498e0dbde CRITICAL 9.8 The Background Image Cropper plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and incl… — wordfence
2f52298b-344b-4561-b1bf-93bea95a3e53
< 1.0.29
CRITICAL 9.8 The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… — wordfence
2f47a01d-b259-465e-bec1-9079987dc5a5
< 2.0.11
CRITICAL 9.8 The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on th… — wordfence
2f0a7d6f-9b95-4052-bab3-85aca01f6ab7
< 1.1.11
CRITICAL 9.8 The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This… — wordfence
2ef5e73e-a627-4e9c-9784-493ace5c8614
< 4.91.9
CRITICAL 9.8 The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execut… — wordfence
2ef21a44-6d03-4197-b49c-d881f9831f46
< 8.9.1
CRITICAL 9.8 The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up… — wordfence
2eeeb4b5-972b-471b-8f0f-a198640fc894
< 3.0
CRITICAL 9.8 The Memphis Documents Library plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… — wordfence
2e88aa9e-6d1d-44ba-8d63-2f4d4161bc9e
< 3.4
CRITICAL 9.8 The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to time-based… — wordfence
2e78cb46-7964-4ba5-b9bf-d47de865dbd2
< 6.3.2
CRITICAL 9.8 The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Privilege Escalation in a… — wordfence
2e6c60bb-d7c9-4925-afbe-00ea847d1f0b CRITICAL 9.8 The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to Remote Code Execution… — wordfence
2e24da0c-13d2-4a3d-b918-0d28e3341d88 CRITICAL 9.8 The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.… — wordfence
2e1ab5a7-0be8-444d-8680-68b3b0be6edf
< 3.29.13
CRITICAL 9.8 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i… — wordfence
2df89ab9-5cc2-46cb-99b2-bc864e960a35
< 2.4.3
CRITICAL 9.8 The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configu… — wordfence
2df449b4-3f3b-4afc-b391-8d8d11710c07
< 2.1.47
CRITICAL 9.8 The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, … — wordfence
2d6e9aea-6ccb-4c83-83bb-63c9c9f59005
< 3.4.12
CRITICAL 9.8 The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticate… — wordfence
2d6cbfc8-1ced-4757-b090-39add17afc77
< 5.3.0
CRITICAL 9.8 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to mi… — wordfence
2d64e1c6-1e25-4438-974d-b7da0979cc40
< 4.2.6.6
CRITICAL 9.8 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜term_i… — wordfence
2d58322f-e24d-40fd-8dab-20752b386bb9 CRITICAL 9.8 The WP REST API FNS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includi… — wordfence
2d35279d-299e-4ca2-8f84-165284e058c8
< 5.9.9.6
CRITICAL 9.8 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via… — wordfence
← Prev 83 84 85 86 87 88 89 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top