🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 88 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1d87d225-7de4-49f8-9cba-391d718af7fd CRITICAL 9.8 The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers t… wordfence
1d7f1283-a274-49a2-8bec-da178771b13a
< 4.11.2
CRITICAL 9.8 The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … wordfence
1d779ad1-fdbe-444c-85c5-99146a1a03d8
< 1.0.5
CRITICAL 9.8 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ima… wordfence
1d640d8e-7730-47e1-9f01-b9656f1ebb1c
< 1.6.1
CRITICAL 9.8 The GrandPrix theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. This make… wordfence
1d54bd25-148f-4e9a-bd31-77b52efd5499 CRITICAL 9.8 The Wp NssUser Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including,… wordfence
1d2b78e0-1b82-4074-8051-e44dcfe3ac51 CRITICAL 9.8 The Compute Links plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 1.2.… wordfence
1cefe584-c1b0-418c-bade-ca4092807b1b
< 2.6
CRITICAL 9.8 The duplicate-post plugin before 2.6 for WordPress has SQL injection. wordfence
1cc1727e-92a6-484d-bdd1-d79aec534df5 CRITICAL 9.8 The Product Lister for eBay plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including,… wordfence
1cbd298c-cba3-4986-b44c-a75b005b4340
< 0.9.7b
CRITICAL 9.8 The The Hacker's Diet plugin for WordPress is vulnerable to SQL Injection via the 'user' parameter in all versions up to… wordfence
1cab1bef-c8c5-45ee-921e-0d01736e74c6 CRITICAL 9.8 The postMash – custom post order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… wordfence
1c7c0c35-5f44-488f-9fe1-269ea4a73854
< 4.10.8
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up… wordfence
1c6bf45b-b02d-43bb-b682-7f1ae994e1d3
< 1.7
CRITICAL 9.8 The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions … wordfence
1c648de5-14b3-4c7f-a1c2-46d91b56b0ff
< 1.11
CRITICAL 9.8 PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allow… wordfence
1c0c6a45-2c4a-4a23-84e6-7a9759796824
< 4.9.56
CRITICAL 9.8 The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnera… wordfence
1bd44471-1a9c-4465-a52a-be64d51e7ea1 CRITICAL 9.8 The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.… wordfence
1bbe01b8-24ed-4e1e-bafc-0f4dea96c1f3
< 2.3.4
CRITICAL 9.8 The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.… wordfence
1bb4674e-71e4-43db-ad9e-36ab15432149
< 4.6.9
CRITICAL 9.8 The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, res… wordfence
1ba55302-b38f-4932-bbba-cdd517380ad7
< 6.9.5
CRITICAL 9.8 WordPress Core is vulnerable to Remote Code Execution in all versions 6.9 to 7.0.1 via the REST API batch request endpoi… wordfence
1b94583f-405e-4fd3-849e-33563b72f698
< 7.2.3
CRITICAL 9.8 The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data du… wordfence
1b5a0c87-59b0-4da4-8949-0957f8e1b479 CRITICAL 9.8 The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the… wordfence
1b4acf11-114a-4e97-89cd-1d387f14a730 CRITICAL 9.8 The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ par… wordfence
1b4630f7-74db-46c4-bf86-f1ff64be3463
< 1.11.10.8
CRITICAL 9.8 The BERTHA AI. Your AI co-pilot for WordPress and Chrome plugin for WordPress is vulnerable to arbitrary file uploads du… wordfence
1b097ab2-7675-4409-b22a-ad70cee35ab1
< 2.5.7.1
CRITICAL 9.8 The GamiPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.7 due to insuffi… wordfence
1ad38d18-689c-41ab-9e33-fccbf6791cdb CRITICAL 9.8 Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0 in /zen-mobile-app-native/server/images.php f… wordfence
1ac218f6-0bfa-480c-9159-d75a027022ba
< 17.8
CRITICAL 9.8 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… wordfence
← Prev 85 86 87 88 89 90 91 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top