🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 87 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
20df30e2-7e59-479c-946d-e0128b7d8401
< 3.7.3
CRITICAL 9.8 The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection. wordfence
20746c92-6e63-47dd-b0f7-9d20bdbdd9cb CRITICAL 9.8 The DesignFolio Plus Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
206c3f15-72d2-4aac-9500-0f794485639e
< 3.0.0
CRITICAL 9.8 Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for Wor… wordfence
205e0b90-0d84-4b16-b968-8ec7770f0695 CRITICAL 9.8 The ACF-Frontend-Display plugin through 2.0.6 for WordPress has arbitrary file upload via an action=upload request to js… wordfence
205a3e43-8ac6-4a0d-86d3-bb433a992e3d
< 1.9
CRITICAL 9.8 The RokIntroScroller plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
20188fd3-c330-4c76-912b-72731e14c450
< 1.6.0
CRITICAL 9.8 The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and… wordfence
200f724e-7911-46d0-82c0-ffa207d8ee17
< 2.4.0
CRITICAL 9.8 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads… wordfence
20077e55-fe75-49c7-ba3f-ccd683a3f722 CRITICAL 9.8 The Vithy theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload… wordfence
1fa39169-1cba-43ce-aa29-adf7ce09ce75
< 1.6.0
CRITICAL 9.8 The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt… wordfence
1f93ecf7-ba49-47f6-abe3-33e3bc6e7054
< 1.1.7
CRITICAL 9.8 Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for Wo… wordfence
1f891b68-72c4-4f94-bd49-52576ad710f9 CRITICAL 9.8 The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing … wordfence
1f714f97-5e1a-498a-9722-1e4bb883c5c7
< 1.2.1
CRITICAL 9.8 Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). Fixed in 1.2.6… wordfence
1f5b4f9a-4067-4514-9027-b645921d807f
< 1.3.0
CRITICAL 9.8 Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the … wordfence
1f4f66fd-189a-4036-8e44-c401647bc655
< 2.1.1
CRITICAL 9.8 The Medicare theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.0 via deser… wordfence
1ef13f92-ae45-411a-b7b4-cdaf299afc8a CRITICAL 9.8 The CoSchool LMS – A complete Learning Management System to Create and Sell Your Courses Online plugin for WordPress i… wordfence
1ec14b1e-6d1a-4451-9fce-ac064623d92f
< 1.4.0
CRITICAL 9.8 The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege… wordfence
1ead6a38-b495-47d2-8d40-1f17e64fd1ff
< 1.8.10.2
CRITICAL 9.8 SQL injection vulnerability in the Contextual Related Posts plugin before 1.8.10.2 for WordPress allows remote attackers… wordfence
1e8f71cc-3197-4cdb-9e3b-a544f689df2d CRITICAL 9.8 The Pathomation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … wordfence
1e65922a-3498-4946-8415-3d922e85e46a
< 4.5.0.2
CRITICAL 9.8 The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.0.1 v… wordfence
1e61cc33-d58e-425e-9835-4d45461edbac CRITICAL 9.8 The Nasa Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.2. This m… wordfence
1e37e54b-9c00-4d04-9c81-791242d45d6c CRITICAL 9.8 The iDump iPhone to WordPress Photo Uploader for WordPress is vulnerable to arbitrary file uploads due to missing file t… wordfence
1decdfd8-a2e8-49af-ade8-01d19814b6fb CRITICAL 9.8 The Flagallery-skins plugin for WordPress is vulnerable to generic SQL Injection via the ‘playlist’ parameter in all… wordfence
1de9183c-95b9-4500-85e2-08dcee956360
< 1.0.5
CRITICAL 9.8 The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… wordfence
1d9ffbf3-520a-4563-85e1-27c1cc544856 CRITICAL 9.8 The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it… wordfence
1d8d393e-764c-491d-8afb-7d4f8d0c387a
< 2.1.0
CRITICAL 9.8 The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password rese… wordfence
← Prev 84 85 86 87 88 89 90 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top