πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 88 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2ad674f7-aff6-432d-9c4c-95aebf8fcf6b
< 2.3.2
CRITICAL 9.8 SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute a… — wordfence
2ad1af69-61e1-4453-866e-1ae71f614f30
< 2.1.7
CRITICAL 9.8 The Membership For WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… — wordfence
2ab6e751-dc23-442f-b22e-ee41fd6651f6
< 2.0.4
CRITICAL 9.8 Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due… — wordfence
2a6c5610-ed84-4d7d-a28f-d3807230e119
< 1.7.0
CRITICAL 9.8 The Web Directory Free plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.6.9 d… — wordfence
2a4caee4-f4fa-45a6-8fe8-d5445bb097bf CRITICAL 9.8 The ListApp Mobile Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versio… — wordfence
2a45fec7-cc69-4df6-98bb-ff70e5b6486c CRITICAL 9.8 The LMS Elementor Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1… — wordfence
2a3e8c29-2e97-48f0-bf72-303857b51511
< 2.0.4
CRITICAL 9.8 The Enable CORS plugin contained a backdoor in all versions up to, and including, 2.0.3. This makes it possible for unau… — wordfence
2a237492-0eb3-46fb-96dc-1959d8a87d1a CRITICAL 9.8 The Stacks Mobile App Builder – The most powerful Mobile Applications Drag and Drop builder plugin for WordPress is vu… — wordfence
2a0671b1-1414-4315-8a2d-bd1aabe091a4
< 6.2.0
CRITICAL 9.8 The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and incl… — wordfence
29e214fd-327b-45c4-a408-7ff56fd29876 CRITICAL 9.8 The Boat Rental Plugin for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… — wordfence
29cbde71-772f-473c-9cad-0c5529b1aa97
< 2.10.3
CRITICAL 9.8 The Backpack Traveler theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.10.2… — wordfence
29cbcbc9-a2a3-4518-a430-969ca76f9bda CRITICAL 9.8 The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including… — wordfence
29ca151b-ef37-4f68-b0ea-b199ad6a4fce
< 1.1.14
CRITICAL 9.8 The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to Local File Inclusion in… — wordfence
29adf3d2-b3a4-43f3-9aaa-bd2cf6cd115b CRITICAL 9.8 Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and event_form.php code do not sanitize input, this … — wordfence
2988bb1f-0a32-4e9b-8096-46476879317b
< 15.6.9
CRITICAL 9.8 The Simple Business Directory Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 15.6.… — wordfence
2971547d-39da-46f1-b62c-1918042ae654
< 3.4
CRITICAL 9.8 The Image News Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… — wordfence
2948d8f6-4b7b-49c3-a917-4306448416ff
< 2.6.4
CRITICAL 9.8 The Houzez Login Register plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2… — wordfence
2945ab15-e211-4a11-954a-002d0fd2a04d
< 1.61.1
CRITICAL 9.8 The Ogami theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.53. This makes i… — wordfence
2927aa13-b012-41eb-93bd-38a4e5fc5455
< 3.19
CRITICAL 9.8 The TicketBAI Facturas para WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficien… — wordfence
290e7b9d-23b6-47bb-9169-d2f9922b6492 CRITICAL 9.8 The Fami Sales Popup plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0.… — wordfence
28cb96a9-12bd-4d9c-ac53-72e81d11b0b6
< 3.0.96
CRITICAL 9.8 The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier… — wordfence
2895f0c2-41b6-4b11-9865-3bded4402aa9
< 5.5.6
CRITICAL 9.8 The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass… — wordfence
2882d9dd-0c73-4c9a-99cb-d10900503103 CRITICAL 9.8 The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. Th… — wordfence
28713983-86ef-45d1-9258-d1a4feedcadd
< 4.08.253
CRITICAL 9.8 The WebinarIgnition – Live, Automated & Evergreen Webinar System also for WooCommerce plugin for WordPress is vulnerab… — wordfence
2851ac4b-a50d-45cd-a472-540932b46d06 CRITICAL 9.8 The DS Ad Rotator plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 0.8.… — wordfence
← Prev 85 86 87 88 89 90 91 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top