🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 91 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
23239fc1-8683-446e-bc61-03d819edf99d CRITICAL 9.8 The DiveBook plugin 1.1.4 for WordPress was prone to a SQL injection within divelog.php, allowing unauthenticated users … — wordfence
23068a98-623d-4eb3-a7c5-6af410de4320
< 5.4.0
CRITICAL 9.8 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all ver… — wordfence
23003405-29c5-41e2-9081-35f05a08a0c3 CRITICAL 9.8 The Arrival theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.5. This make… — wordfence
22dd9fbb-77d2-48cd-91a5-eba39ef9d2c1
< 2.5.2
CRITICAL 9.8 The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Privilege Escalation… — wordfence
22dced08-20b1-4f21-8c43-148d40a29701 CRITICAL 9.8 The ReFormer – Multichannel Contact Form for Elementor plugin for WordPress is vulnerable to arbitrary file uploads du… — wordfence
22cfa0da-9370-4d95-8b23-024447fd84cd CRITICAL 9.8 The Xews Lite theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.9. This ma… — wordfence
22a42dc3-0b9b-47c8-9236-5dc3b58149c5 CRITICAL 9.8 SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 3.4.1 and below for WordPress allows r… — wordfence
227fb6d1-3515-4172-9d7c-57a66d17858f
< 8.0.27
CRITICAL 9.8 The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This r… — wordfence
2259ae51-447c-431d-97af-7fddefb0f349 CRITICAL 9.8 The Grand Restaurant WordPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl… — wordfence
2250fa2d-82f5-4553-a52e-0c43d215aaba
< 0.4.3
CRITICAL 9.8 Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow … — wordfence
22356f42-af5e-4479-919c-9ceac42e686f
< 14.8
CRITICAL 9.8 Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows r… — wordfence
22351b90-fc34-44ce-9241-4a0f01eb7b1c
< 2.0.1
CRITICAL 9.8 The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers… — wordfence
222e0f27-f269-4751-9544-1a6cb03ab3a7
< 1.8.6
CRITICAL 9.8 The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi… — wordfence
2205a0c8-0834-440b-9fee-3223de05a3ac
< 5.4.0
CRITICAL 9.8 The K Elements plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.3.9. … — wordfence
21e4b1fe-993b-4898-a523-e0a858c30a38
< 1.33
CRITICAL 9.8 The TagGator plugin for WordPress is vulnerable to generic SQL Injection via the ‘tagid’ parameter in versions up to… — wordfence
21d244f4-f0cd-4d4d-8c6a-edea6b7b8145
< 34.06
CRITICAL 9.8 Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPre… — wordfence
21a1b117-945f-49bc-9ea1-313afa93bf32
< 4.0.10
CRITICAL 9.8 The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps… — wordfence
21930a4f-2f78-42c5-8ffa-2993333db2fe
< 3.1.3
CRITICAL 9.8 The Ultimate Product Catalogue for WordPress is vulnerable to SQL Injection via the ‘Item_ID’ and 'SingleProduct' pa… — wordfence
215f5ab4-44be-4db0-86d5-e7ff0630e15d
< 1.4.6
CRITICAL 9.8 The Material Dashboard plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.… — wordfence
215aaad5-bf34-4817-a220-7077e9aa808b
< 1.5.4
CRITICAL 9.8 The AI Copilot – Content Generator plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a… — wordfence
21456889-058c-46a5-80c3-a0c8f90cd3bf
< 2.82
CRITICAL 9.8 In the Media Library Assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta… — wordfence
20df30e2-7e59-479c-946d-e0128b7d8401
< 3.7.3
CRITICAL 9.8 The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection. — wordfence
20746c92-6e63-47dd-b0f7-9d20bdbdd9cb CRITICAL 9.8 The DesignFolio Plus Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … — wordfence
206c3f15-72d2-4aac-9500-0f794485639e
< 3.0.0
CRITICAL 9.8 Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for Wor… — wordfence
205e0b90-0d84-4b16-b968-8ec7770f0695 CRITICAL 9.8 The ACF-Frontend-Display plugin through 2.0.6 for WordPress has arbitrary file upload via an action=upload request to js… — wordfence
← Prev 88 89 90 91 92 93 94 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top