πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 9 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fca20535-d033-45d5-acc3-72ad53d34b4f
< 3.3
CRITICAL 9.8 The Login as User or Customer plugin for WordPress is vulnerable to authorization bypass due to improper authorization c… wordfence
fca11e5b-2b6c-42f0-baf3-4ee023535f83 CRITICAL 9.8 The lim4wp plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploa… wordfence
fc747d1a-9d95-4127-8bb9-13dc2beb1874 CRITICAL 9.8 The Stacks Mobile App Builder – The most powerful Mobile Applications Drag and Drop builder plugin for WordPress is vu… wordfence
fc6dcf93-7f1f-4e87-8ba5-852d23b1f0fd
< 4.2
CRITICAL 9.8 The Jetpack plugin for WordPress is vulnerable to timing attacks in versions up to, and including, 4.1.x. This is due to… wordfence
fbf2aeed-0f18-4ef6-aff8-9e8c4531d789
< 3.1.8
CRITICAL 9.8 The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to… wordfence
fbdd01b3-153b-4783-b686-558874d2856e CRITICAL 9.8 Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player)… wordfence
fbdc0074-f357-455e-8f17-0821494ea550
< 6.3.6
CRITICAL 9.8 The WP Travel Engine plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.5.… wordfence
fbd978fd-f759-4983-90b0-af7338e21d30
< 5.0.1.8
CRITICAL 9.8 The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including … wordfence
fbc8c188-dd68-481c-9584-f9d856db8b7d
< 2.1.1
CRITICAL 9.8 The g-FFL Checkout plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… wordfence
fbba5284-917a-4056-a798-b4d155c58313
< 3.2.0
CRITICAL 9.8 The WP Event Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.51… wordfence
fb7112bb-c76a-4665-b891-8c388ce05d51
< 4.2.2
CRITICAL 9.8 The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Privile… wordfence
fb66378c-4e64-4f05-a466-72a3c2d0b330
< 5.6
CRITICAL 9.8 The Events Manager plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 5.5.7.1. This … wordfence
fb5a65a2-e748-4c23-8cae-cb0a7de74911
< 4.13.0
CRITICAL 9.8 An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote … wordfence
fb11ad61-4ee7-45d2-a8e4-388f86bf4a0e
< 2.3.1
CRITICAL 9.8 The Joy Of Text Lite plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and i… wordfence
fae8a397-bbe9-4acf-a35e-9bad67df69f1 CRITICAL 9.8 The GRÜN spendino Spendenformular – Mehr Spenden! Weniger Arbeit! plugin for WordPress is vulnerable to unauthorized … wordfence
facba004-fc2a-4ba0-aabf-551b5f11e567
< 1.5.4
CRITICAL 9.8 The Fediverse Embeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
fac29bb3-e534-4bee-9974-5ccac7d445db
< 1.6.3
CRITICAL 9.8 The Daily Edition theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… wordfence
fabc7ad3-1d20-493f-aacb-1832d33d8e14
< 2.12.1
CRITICAL 9.8 The Porto Theme - Functionality plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.… wordfence
faa3f6ab-43d6-4874-b16e-93abbb4ba72e
< 1.9
CRITICAL 9.8 The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sav… wordfence
fa86b98c-9690-4ef6-ac50-895035ed2b55 CRITICAL 9.8 The Smart Slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via… wordfence
fa8124db-ee6a-481d-88c6-4cc84fefcf1c
< 2.2.1
CRITICAL 9.8 The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,… wordfence
fa7e74ee-fd66-41e2-babd-06bdfb32d013
< 4.1.7.2
CRITICAL 9.8 The LearnPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.7.1 via … wordfence
fa45d830-fa28-4d94-a6d5-2dc2b8456cf2
< 2.0.4
CRITICAL 9.8 The "WordPress Automatic Plugin" plugin for WordPress is vulnerable to generic SQL Injection via the β€˜q’ parameter i… wordfence
fa412364-2e22-439f-8f94-2c525cfbf1a7 CRITICAL 9.8 The Saoshyant Slider plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0 vi… wordfence
fa2bc3ae-1162-496b-8bc3-5bee1c0ff702
< 1.2.7
CRITICAL 9.8 The Cherry Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and lack of … wordfence
← Prev 6 7 8 9 10 11 12 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top