🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 86 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
236bb9a8-49f7-4b75-a0b1-fa4ff65394f8 CRITICAL 9.8 The HotStar – Multi-Purpose Business Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to… wordfence
235c9967-808f-45f2-85cf-7ee7a523593d
< 1.5.16
CRITICAL 9.8 Multiple SQL injection vulnerabilities in the ratings module in the Users Ultra plugin before 1.5.16 for WordPress allow… wordfence
233a75c7-9e45-4509-8f7c-584e2f5b38c7
< 14.4.5
CRITICAL 9.8 The StoreKeeper for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… wordfence
23399606-20b6-4d0b-b613-06dc838dc1e7
< 2.9.5
CRITICAL 9.8 The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … wordfence
232dd4fa-748e-4b65-8b78-7b2d8e9831aa
< 7.3.19.727
CRITICAL 9.8 A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPres… wordfence
23239fc1-8683-446e-bc61-03d819edf99d CRITICAL 9.8 The DiveBook plugin 1.1.4 for WordPress was prone to a SQL injection within divelog.php, allowing unauthenticated users … wordfence
23068a98-623d-4eb3-a7c5-6af410de4320 CRITICAL 9.8 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all ver… wordfence
23003405-29c5-41e2-9081-35f05a08a0c3 CRITICAL 9.8 The Arrival theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.5. This make… wordfence
22dd9fbb-77d2-48cd-91a5-eba39ef9d2c1
< 2.5.2
CRITICAL 9.8 The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Privilege Escalation… wordfence
22dced08-20b1-4f21-8c43-148d40a29701 CRITICAL 9.8 The ReFormer – Multichannel Contact Form for Elementor plugin for WordPress is vulnerable to arbitrary file uploads du… wordfence
22cfa0da-9370-4d95-8b23-024447fd84cd CRITICAL 9.8 The Xews Lite theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.9. This ma… wordfence
22a42dc3-0b9b-47c8-9236-5dc3b58149c5 CRITICAL 9.8 SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 3.4.1 and below for WordPress allows r… wordfence
227fb6d1-3515-4172-9d7c-57a66d17858f
< 8.0.27
CRITICAL 9.8 The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This r… wordfence
2259ae51-447c-431d-97af-7fddefb0f349 CRITICAL 9.8 The Grand Restaurant WordPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl… wordfence
2250fa2d-82f5-4553-a52e-0c43d215aaba
< 0.4.3
CRITICAL 9.8 Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow … wordfence
22356f42-af5e-4479-919c-9ceac42e686f
< 14.8
CRITICAL 9.8 Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows r… wordfence
22351b90-fc34-44ce-9241-4a0f01eb7b1c
< 2.0.1
CRITICAL 9.8 The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers… wordfence
2205a0c8-0834-440b-9fee-3223de05a3ac
< 5.4.0
CRITICAL 9.8 The K Elements plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.3.9. … wordfence
21e4b1fe-993b-4898-a523-e0a858c30a38
< 1.33
CRITICAL 9.8 The TagGator plugin for WordPress is vulnerable to generic SQL Injection via the ‘tagid’ parameter in versions up to… wordfence
21d244f4-f0cd-4d4d-8c6a-edea6b7b8145
< 34.06
CRITICAL 9.8 Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPre… wordfence
21a1b117-945f-49bc-9ea1-313afa93bf32
< 4.0.10
CRITICAL 9.8 The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps… wordfence
21930a4f-2f78-42c5-8ffa-2993333db2fe
< 3.1.3
CRITICAL 9.8 The Ultimate Product Catalogue for WordPress is vulnerable to SQL Injection via the ‘Item_ID’ and 'SingleProduct' pa… wordfence
215f5ab4-44be-4db0-86d5-e7ff0630e15d
< 1.4.6
CRITICAL 9.8 The Material Dashboard plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.… wordfence
215aaad5-bf34-4817-a220-7077e9aa808b
< 1.5.4
CRITICAL 9.8 The AI Copilot – Content Generator plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a… wordfence
21456889-058c-46a5-80c3-a0c8f90cd3bf
< 2.82
CRITICAL 9.8 In the Media Library Assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta… wordfence
← Prev 83 84 85 86 87 88 89 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top