πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 89 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1aac7677-53f4-4944-9bdc-7e07b09c6c13
< 1.5
CRITICAL 9.8 The ND Restaurant Reservations plugin before 1.5 for WordPress is vulnerable to unauthenticated option changes via the n… wordfence
1a74252c-1385-4ee7-aeaa-f0476336b1e6 CRITICAL 9.8 The Umberto theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.8 via deseri… wordfence
1a4cc739-0563-4ca2-931d-818a0c285257
< 1.5.5
CRITICAL 9.8 SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attack… wordfence
1a385af7-4094-4a1e-9f1f-6291698f71af
< 11.1.0
CRITICAL 9.8 The SUMO Affiliates Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
1a14b674-620e-4247-a200-92d9f23acbca
< 1.6.49.10
CRITICAL 9.8 The ThemeREX Addons plugin for WordPress is vulnerable to Improper Access Control in various versions. This is due to th… wordfence
19f737a8-21e6-49d3-95b9-24fb6e5d7af7
< 2.1.2.1
CRITICAL 9.8 The InPost Gallery Plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 vi… wordfence
19d1c0ee-9f9b-42a1-8d25-f8ba07e15b0c CRITICAL 9.8 The Motors - Events plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.7. … wordfence
19c824ce-40e2-44fb-a356-6a02bd13cc67
< 2.5.5
CRITICAL 9.8 The Residential Address Detection plugin for WordPress is vulnerable to unauthorized modification of data that can lead … wordfence
19c370f1-322b-4c35-b100-244547373e1a CRITICAL 9.8 The User Post Gallery - UPG plugin for WordPress is vulnerable to authorization bypass which leads to remote command exe… wordfence
19bf7a68-e76d-4740-9f35-b6084094f59b
< 1.6.10
CRITICAL 9.8 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in th… wordfence
19868c11-67a7-420f-911d-520e00f2f4f5 CRITICAL 9.8 The Houzez Login Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin… wordfence
194f71d8-43d7-4a1f-8390-2c1efd0b0a23
< 0.2.28
CRITICAL 9.8 The ActiveDEMAND plugin for WordPress is vulnerable to unauthenticated post updates and deletion due to missing authoriz… wordfence
1932c9b4-2fea-40f8-9748-09ded8143c11
< 4.963
CRITICAL 9.8 The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file re… wordfence
18fd631d-9e9b-46ee-953f-61ad3458e1dd
< 2.7.6
CRITICAL 9.8 The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account,… wordfence
18e562fb-9035-4f2d-a2d3-9a74ff1e4e32 CRITICAL 9.8 The Ketchup Restaurant Reservations plugin for WordPress is vulnerable to blind SQL Injection in versions up to, and inc… wordfence
189d22e0-c16a-48ab-a278-a132cd1057b6
< 1.9.0
CRITICAL 9.8 An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-For… wordfence
1898fbe5-de5d-45e3-95be-db500f093908
< 1.1.1
CRITICAL 9.8 The Lasa theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. This makes it … wordfence
187df8e0-80f0-4805-823b-80627b76db2a CRITICAL 9.8 The Facebook Survey Pro plugin for WordPress is vulnerable to generic SQL Injection via the β€˜id’ parameter in versio… wordfence
18739406-fa04-4045-9539-4e943dfe6084 CRITICAL 9.8 The Winnex theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.2. This makes… wordfence
186517cd-e444-457a-9e10-583f41595511
< 1.0.4
CRITICAL 9.8 The Easy Digital Downloads – Upload File for WordPress is vulnerable to Arbitrary File Upload/Delete and Remote Code E… wordfence
185d692c-bc67-44de-82c7-bcbe454dc178 CRITICAL 9.8 The Contact Form 7 Campaign Monitor Extension plugin for WordPress is vulnerable to arbitrary file deletion due to insuf… wordfence
18557f4a-05b2-4cb4-afef-19c5c63c37a4 CRITICAL 9.8 The "LB Mixed Slideshow for WordPress" plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … wordfence
18368ad4-4c35-4b08-8297-2ebdf1bb6e46
< 2.8.9
CRITICAL 9.8 The Ezoic plugin for WordPress is vulnerable to authorization bypass to stored cross-site scripting via several REST-API… wordfence
1833720c-e714-4ec5-9ebb-24a4612195d6
< 2.3.2
CRITICAL 9.8 The Work The Flow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… wordfence
182370f5-0f56-4757-8276-1399606c1a2d
< 1.44
CRITICAL 9.8 Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when r… wordfence
← Prev 86 87 88 89 90 91 92 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top