🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 89 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
284eafb9-94bc-4478-abff-f7dafd510a1d
< 4.1.3
CRITICAL 9.8 The Simple Membership plugin for WordPress is vulnerable to membership related privilege escalation in versions up to, a… — wordfence
283b10e6-61ae-4e1d-be7b-a63aece6ffda
< 4.2.23
CRITICAL 9.8 The Etoile Ultimate Product Catalog plugin 4.2.22 for WordPress has SQL injection with these wp-admin/admin-ajax.php POS… — wordfence
282a26e8-4848-4e40-bfe5-fe2ba40f198e
< 1.0.34
CRITICAL 9.8 Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow rem… — wordfence
27f90d97-c62f-4591-ba26-8d204d567687
< 2.5.0
CRITICAL 9.8 The Avantage theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4.9 via deser… — wordfence
27bb60c1-43fa-4a18-b9ca-059535b0d5b6
< 1.1.20
CRITICAL 9.8 The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in al… — wordfence
2742cc47-8e3d-4fe4-b653-7310a4156a84
< 1.3.1
CRITICAL 9.8 The aDirectory – Directory Listing WordPress Plugin plugin for WordPress is vulnerable to arbitrary file uploads due t… — wordfence
271b151c-5646-4206-a7db-739ac36a9fdd CRITICAL 9.8 The 1-Click Login: Passwordless Authentication plugin for WordPress is vulnerable to authentication bypass in version 1.… — wordfence
271a35fb-56b7-4d6b-bccc-fea1227d0913 CRITICAL 9.8 The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… — wordfence
2710b445-4281-4055-be37-56902ae1d1b6
< 2.0.66.1
CRITICAL 9.8 The Yozi theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.63. This makes … — wordfence
26f4e785-724b-41d3-b479-cb0150e70f9e CRITICAL 9.8 The Advanced Booking Calendar for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.1 due t… — wordfence
26d83a9d-3e51-450e-b3cb-7c53a4bcba60 CRITICAL 9.8 The PICA Photo Gallery plugin for WordPress is vulnerable to SQL Injection via the ‘aid’ parameter in versions up to… — wordfence
2693ae37-790d-4b18-a9ec-054c8c27b8bc
< 3.4.4
CRITICAL 9.8 The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3… — wordfence
268b77b9-af1d-41c8-9f24-99b60eb04cc4
< 3.4.3
CRITICAL 9.8 The ConvertPlug plugin for WordPress is vulnerable to Unauthenticated Administrator Creation in versions up to, and incl… — wordfence
2685a2b4-aba3-425b-af0d-06f7693ab3d7
< 1.1.5
CRITICAL 9.8 The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due t… — wordfence
2655ec9f-471f-48e7-8e1c-a428ef3b46ee CRITICAL 9.8 Unrestricted file upload vulnerability in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote att… — wordfence
2652a7fc-b610-40f1-8b76-2129f59390ec
< 3.8.0
CRITICAL 9.8 The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in … — wordfence
263ac05d-f1ca-46e3-a43e-3b45eb8066d4
< 1.56.2
CRITICAL 9.8 The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1… — wordfence
2637e273-a308-4033-be5a-2f778f8df282
< 1.2.2
CRITICAL 9.8 The Create Block Theme plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization via the… — wordfence
262e3bb3-bc83-4d0b-8056-9f94ec141b8f
< 6.05
CRITICAL 9.8 The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '… — wordfence
26153183-45f1-4694-94ec-f547f1b99089 CRITICAL 9.8 The Recently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1 via deseri… — wordfence
26140315-04c7-4056-a570-865cd4ffe85e
< 7.0.2
CRITICAL 9.8 The Quiz and Survey Master plugin for WordPress is vulnerable to arbitrary file uploads due to missing filename sanitiza… — wordfence
2597724a-9a39-4e46-b153-f42366f833ba
< 1.5.6.1
CRITICAL 9.8 All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to … — wordfence
25971f3f-4816-416c-9de9-feb6326fe948
< 6.5
CRITICAL 9.8 The Super Store Finder plugin in versions up to, and including 6.4 and the Super Interactive Maps plugin in versions up … — wordfence
259158f0-390a-458f-9d8e-262006c4c18d
< 1.0.7
CRITICAL 9.8 The Really Simple Guest Post plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… — wordfence
256c4984-eee8-4ed0-ba34-e022822d6387 CRITICAL 9.8 The Private Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.1… — wordfence
← Prev 86 87 88 89 90 91 92 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top