πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 87 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2d29c30c-bb42-4ed0-a78d-eeea5b256275
< 1.71.0
CRITICAL 9.8 The ark-core plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.70.0. T… — wordfence
2d23a2b9-8476-4564-a5de-5e6cfc38ce68
< 1.6.6
CRITICAL 9.8 The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.… — wordfence
2d10f043-df2c-4e81-bd99-e478a2dca0cf CRITICAL 9.8 The WordPress Shout Box Widget plugin is vulnerable to generic SQL Injection via the 'class_qshout.php' file in versions… — wordfence
2d048878-12ae-442a-921d-c02a4e1e3974
< 34.06
CRITICAL 9.8 Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to exec… — wordfence
2ceba97c-8dfe-4195-87f7-5835efa1cd1f
< 1.4.0
CRITICAL 9.8 The Checkout Field Visibility for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up … — wordfence
2cd71719-e900-46c8-884e-b485c62fed00
< 4.9.37
CRITICAL 9.8 The ManageWP Worker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to 4.9.37 (exclusive)… — wordfence
2cb40ada-03db-49ed-9f0d-84177238710b CRITICAL 9.8 The Support Ticket Management System for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all ver… — wordfence
2cb252c9-fd84-439a-9e7f-05a6000912eb
< 1.1.8
CRITICAL 9.8 The Meta News theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.7. This ma… — wordfence
2c9fa6f9-a549-4629-862f-f9a47b13aa59
< 3.11.9
CRITICAL 9.8 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… — wordfence
2c8a2446-60c1-4641-9b5c-229327724333 CRITICAL 9.8 The Goodlayers Hostel plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.1.2… — wordfence
2c7a0b51-6626-449f-95f5-74c4847909de
< 2.1.4.1
CRITICAL 9.8 The InPost Gallery Plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.4 vi… — wordfence
2c5bb593-59b5-4760-8d54-14d7665c7e7f
< 6.03.01
CRITICAL 9.8 The Event Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.02… — wordfence
2c4c1a16-bbdc-4751-9c5b-ddc0eb586c3f
< 2.2.0
CRITICAL 9.8 The Single Sign On For TNG plugin for WordPress is vulnerable to privilege escalation via account takeover in all versio… — wordfence
2c4615d4-92b4-45d3-9fb7-66c9f5d6bdd2 CRITICAL 9.8 The GetShop ecommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3. … — wordfence
2c34c79d-7eb9-4474-8189-26cc4316ba8e
< 1.7.7
CRITICAL 9.8 The Authora : Easy login with mobile number plugin for WordPress is vulnerable to Privilege Escalation in all versions u… — wordfence
2c1e6298-f243-49a5-b1b7-52bd6a6c8858
< 1.1
CRITICAL 9.8 The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulne… — wordfence
2be770c7-7aa2-430b-981d-5d81fe068bef
< 1.3.33
CRITICAL 9.8 The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable… — wordfence
2be3638e-3a0d-40e5-914e-9f20971abf9a CRITICAL 9.8 SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remo… — wordfence
2bc8c04f-3764-473e-a216-7c5dc49abfa8 CRITICAL 9.8 SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote… — wordfence
2b69f90a-1dd3-4184-aee3-9b0251b981cc
< 2.6.11
CRITICAL 9.8 The WP Migrate Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.… — wordfence
2b6489f8-061d-4fbd-81f2-9f508dd0e7f8
< 3.3.1
CRITICAL 9.8 An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allo… — wordfence
2b5a57d2-13bb-43d8-b495-e1d4d933b138
< 4.0.19
CRITICAL 9.8 The Eyewear prescription form plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p… — wordfence
2b24693f-6b69-4dfb-a18c-e929db09d020
< 1.4.6
CRITICAL 9.8 The Pagelines Theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the pagelin… — wordfence
2b0198c8-4be8-44e0-9728-d5d2aa376796
< 2.0
CRITICAL 9.8 The WooCommerce PPOM plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… — wordfence
2ae44bcb-6149-4661-8890-23c867e9a918
< 2.0.0
CRITICAL 9.8 The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc… — wordfence
← Prev 84 85 86 87 88 89 90 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top