πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 90 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2565852f-43df-41b1-949e-6c02a8946407
< 3.0.0
CRITICAL 9.8 The Sitepact's Contact Form 7 Extension For Klaviyo plugin for WordPress is vulnerable to SQL Injection parameter in ver… — wordfence
25627b5c-958c-45ad-8450-8dfccdfdac31 CRITICAL 9.8 The Radykal Fancy Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… — wordfence
2513a199-30a8-45a9-80b3-1f6e51534c88 CRITICAL 9.8 The Nightlife Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the up… — wordfence
24f31bbf-883f-4903-847a-7bfc3e45654c CRITICAL 9.8 The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and im… — wordfence
24e8d1a4-9853-4f60-a371-7fdbe86d554b
< 12.4
CRITICAL 9.8 The tagDiv Cloud Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… — wordfence
24d081e3-4291-427c-bf2c-726d93aa00ac
< 1.4
CRITICAL 9.8 The filedownload plugin for WordPress is vulnerable to blind SQL Injection in versions before 1.4 due to insufficient es… — wordfence
24c9a333-e60e-481b-ba27-65094f4f8d39
< 5.0.7
CRITICAL 9.8 The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads … — wordfence
24a88f20-ddc4-4544-ac18-ed538ecfa1c7 CRITICAL 9.8 Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1 in csv2wpecCoupon_FileUpload.php file. — wordfence
2491d502-8087-4e95-b047-a3b196322d94
< 4.7.4
CRITICAL 9.8 The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user inp… — wordfence
2489e649-27f7-4ca0-8655-0957016fa89a CRITICAL 9.8 The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to ins… — wordfence
247ee5bf-1e77-4461-b9f7-28b051b78af7 CRITICAL 9.8 The Real Estate Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.3… — wordfence
24517dc6-4995-48ee-9b02-5c7c29d359f6
< 3.05.1
CRITICAL 9.8 The Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin fo… — wordfence
2450277e-589d-4153-bd3f-ffed1a8b4340 CRITICAL 9.8 The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/downl… — wordfence
244b6773-8983-4435-8d1c-240bcc54e061 CRITICAL 9.8 The Lis Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.2.1… — wordfence
240cc19a-9bae-4e69-a16f-46901daaa945
< 3.0.1
CRITICAL 9.8 The Brandfolder – Digital Asset Management Simplified. plugin for WordPress is vulnerable to Local and Remote File Inc… — wordfence
24092cd1-cf89-49c1-a607-4d5d06d0c804 CRITICAL 9.8 The IP Loc8 plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1 via deseria… — wordfence
23fbb011-cf60-4c75-ac68-b5d0dfa3c356
< 1.6.7
CRITICAL 9.8 Server-Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter. — wordfence
23da892a-62c1-4c4b-8b86-4b55018c309b CRITICAL 9.8 The WPSPX plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.2. This m… — wordfence
23c99d3c-5ee5-4793-92a4-f49bf345c634 CRITICAL 9.8 The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Remote C… — wordfence
23aa8a2f-9238-4d93-b2d2-de7838ccb156
< 1.5.5
CRITICAL 9.8 SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5. — wordfence
236bb9a8-49f7-4b75-a0b1-fa4ff65394f8 CRITICAL 9.8 The HotStar – Multi-Purpose Business Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to… — wordfence
235c9967-808f-45f2-85cf-7ee7a523593d
< 1.5.16
CRITICAL 9.8 Multiple SQL injection vulnerabilities in the ratings module in the Users Ultra plugin before 1.5.16 for WordPress allow… — wordfence
233a75c7-9e45-4509-8f7c-584e2f5b38c7
< 14.4.5
CRITICAL 9.8 The StoreKeeper for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… — wordfence
23399606-20b6-4d0b-b613-06dc838dc1e7
< 2.9.5
CRITICAL 9.8 The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … — wordfence
232dd4fa-748e-4b65-8b78-7b2d8e9831aa
< 7.3.19.727
CRITICAL 9.8 A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPres… — wordfence
← Prev 87 88 89 90 91 92 93 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top