πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 90 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
181eb0e4-3529-4069-91b4-6f6c6ee2c786 CRITICAL 9.8 The UsersControl – Users Profile, Free or Paid Subscriptions, User Access Restriction & Members Directory plugin for … wordfence
181e41d6-1599-4229-ace8-0bdb5735858f CRITICAL 9.8 wordfence
1814ad55-0807-4def-b584-6dbbc5d6eb72
< 3.10
CRITICAL 9.8 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to Local File Inclusion in versions… wordfence
1814537d-8307-4d1f-86c8-801519172be5
< 1.7
CRITICAL 9.8 The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missi… wordfence
17dcacaf-0e2a-4bef-b944-fb7e43d25777
< 2.7.3
CRITICAL 9.8 The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the β€˜cnt’ and 'sid' para… wordfence
17d8e2e9-5e3f-433b-be1a-6ea765eba547
< 4.15.0
CRITICAL 9.8 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication by… wordfence
17ccf3f5-ac71-4827-bf11-9a5199f8752e CRITICAL 9.8 The AJAX Random Posts plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.3.3… wordfence
17cc137e-da04-42ea-9336-24c4e0b9264a CRITICAL 9.8 The Devexhub Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
1789b78a-4733-40b9-b28f-f63aeb4c0f0b
< 2.10.0
CRITICAL 9.8 The TI WooCommerce Wishlist plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
178911d9-0552-4f44-aae5-06fc9734cfac
< 5.9.6
CRITICAL 9.8 The Event post plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.9.5 vi… wordfence
17641096-1c7f-43f7-90d6-14c368c95d72 CRITICAL 9.8 The Advanced Personalization plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… wordfence
16e3ca1b-817d-4f03-92ae-346a56271c47
< 3.2.0
CRITICAL 9.8 A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign… wordfence
16c0a3b7-25b0-457e-b883-a780bc6a29a7 CRITICAL 9.8 The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter… wordfence
16bce38a-07fa-43b7-aacb-6c932c3d0987
< 7.7.2
CRITICAL 9.8 The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using … wordfence
16af4d96-e7e0-4b13-90a5-ddf62909271a CRITICAL 9.8 The Contus Video Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
169d06e1-055b-422a-a466-155ec43e0dbb
< 6.8
CRITICAL 9.8 The Simple User Registration plugin for WordPress is vulnerable to privilege escalation due to a missing capability chec… wordfence
167436b7-3d2b-46fc-a1bc-2bcfd899182e
< 4.7.6
CRITICAL 9.8 The Noo JobMonster theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7.5… wordfence
1672e8fb-900b-4c2a-b9fd-e64dbb1046af CRITICAL 9.8 The user files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… wordfence
162a9203-d169-4d96-9839-110f6a9e4ad3
< 1.5.3
CRITICAL 9.8 The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the… wordfence
15fecefa-f1f1-47f3-8ad7-ec7772ecafc4 CRITICAL 9.8 Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 a… wordfence
15deb0db-5a13-4018-88e5-5f5cb61bd495
< 1.2
CRITICAL 9.8 The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter. wordfence
1560b740-4018-4b08-9399-2fc87e16ea7b
< 1.1.1
CRITICAL 9.8 The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling. wordfence
155e3de1-e115-4683-bb4d-a0c5667dc3d3
< 3.3.0
CRITICAL 9.8 The WP Post Author plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.2.3. T… wordfence
1540bf3e-2928-476c-8e5b-241b80dd699f
< 4.3.7
CRITICAL 9.8 The RealHomes theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.3.6. Thi… wordfence
153e435b-9986-4242-a89b-12e8f1552803
< 1.0.1
CRITICAL 9.8 The Zendrop – Global Dropshipping plugin for WordPress is vulnerable to generic SQL Injection via the setMetaData func… wordfence
← Prev 87 88 89 90 91 92 93 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top