🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 9 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fced0686-f56d-4163-80fd-362ee652d148
< 3.6.8
CRITICAL 9.8 The WP Timeline – Vertical and Horizontal timeline plugin plugin for WordPress is vulnerable to Local File Inclusion i… — wordfence
fccfe581-16aa-4a6e-a6aa-60c05e4d26cb
< 3.2.0
CRITICAL 9.8 The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders i… — wordfence
fcc78fa6-a5f0-4f29-ae19-8e783698b19e
< 1.9.5
CRITICAL 9.8 The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to… — wordfence
fca20535-d033-45d5-acc3-72ad53d34b4f
< 3.3
CRITICAL 9.8 The Login as User or Customer plugin for WordPress is vulnerable to authorization bypass due to improper authorization c… — wordfence
fca11e5b-2b6c-42f0-baf3-4ee023535f83 CRITICAL 9.8 The lim4wp plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploa… — wordfence
fc747d1a-9d95-4127-8bb9-13dc2beb1874 CRITICAL 9.8 The Stacks Mobile App Builder – The most powerful Mobile Applications Drag and Drop builder plugin for WordPress is vu… — wordfence
fc6dcf93-7f1f-4e87-8ba5-852d23b1f0fd
< 4.2
CRITICAL 9.8 The Jetpack plugin for WordPress is vulnerable to timing attacks in versions up to, and including, 4.1.x. This is due to… — wordfence
fbf2aeed-0f18-4ef6-aff8-9e8c4531d789
< 3.1.8
CRITICAL 9.8 The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to… — wordfence
fbdd01b3-153b-4783-b686-558874d2856e CRITICAL 9.8 Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player)… — wordfence
fbdc0074-f357-455e-8f17-0821494ea550
< 6.3.6
CRITICAL 9.8 The WP Travel Engine plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.5.… — wordfence
fbd978fd-f759-4983-90b0-af7338e21d30
< 5.0.1.8
CRITICAL 9.8 The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including … — wordfence
fbc8c188-dd68-481c-9584-f9d856db8b7d
< 2.1.1
CRITICAL 9.8 The g-FFL Checkout plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… — wordfence
fbba5284-917a-4056-a798-b4d155c58313
< 3.2.0
CRITICAL 9.8 The WP Event Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.51… — wordfence
fb7112bb-c76a-4665-b891-8c388ce05d51
< 4.2.2
CRITICAL 9.8 The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Privile… — wordfence
fb66378c-4e64-4f05-a466-72a3c2d0b330
< 5.6
CRITICAL 9.8 The Events Manager plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 5.5.7.1. This … — wordfence
fb5a65a2-e748-4c23-8cae-cb0a7de74911
< 4.13.0
CRITICAL 9.8 An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote … — wordfence
fb11ad61-4ee7-45d2-a8e4-388f86bf4a0e
< 2.3.1
CRITICAL 9.8 The Joy Of Text Lite plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and i… — wordfence
fae8a397-bbe9-4acf-a35e-9bad67df69f1 CRITICAL 9.8 The GRÜN spendino Spendenformular – Mehr Spenden! Weniger Arbeit! plugin for WordPress is vulnerable to unauthorized … — wordfence
facba004-fc2a-4ba0-aabf-551b5f11e567
< 1.5.4
CRITICAL 9.8 The Fediverse Embeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… — wordfence
fac29bb3-e534-4bee-9974-5ccac7d445db
< 1.6.3
CRITICAL 9.8 The Daily Edition theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… — wordfence
fabc7ad3-1d20-493f-aacb-1832d33d8e14
< 2.12.1
CRITICAL 9.8 The Porto Theme - Functionality plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.… — wordfence
faa3f6ab-43d6-4874-b16e-93abbb4ba72e
< 1.9
CRITICAL 9.8 The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sav… — wordfence
fa910b80-a496-449c-8227-de7defa1f2ae CRITICAL 9.8 The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0… — wordfence
fa86b98c-9690-4ef6-ac50-895035ed2b55 CRITICAL 9.8 The Smart Slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via… — wordfence
fa8124db-ee6a-481d-88c6-4cc84fefcf1c
< 2.2.1
CRITICAL 9.8 The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,… — wordfence
← Prev 6 7 8 9 10 11 12 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top