πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 91 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
14f86410-a21c-43ee-8d78-6fcce3a5b99b CRITICAL 9.8 The Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '/u… wordfence
14d48a81-c6b5-415f-8c82-5fd40b2e790a
< 1.7.0
CRITICAL 9.8 A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successfu… wordfence
14a1b8af-bd32-4245-92d6-549cae68c626
< 6.9.0
CRITICAL 9.8 The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to w… wordfence
14981949-271c-4f98-a6a1-b00619f1436d
< 1.1
CRITICAL 9.8 The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0… wordfence
146c8783-ba59-41da-9e95-7401865b7b8c
< 2.5.17
CRITICAL 9.8 SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote atta… wordfence
144df910-67d2-4e3b-9ccf-04ebd5d1bf8b
< 1.5.4.9
CRITICAL 9.8 SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allo… wordfence
13b4efa1-3f52-476c-80fe-b36ccb62a24b
< 3.0.5
CRITICAL 9.8 The Podcasting Plugin by TSG plugin for WordPress is vulnerable to Remote File Inclusion of media files in versions up t… wordfence
13b2fb59-35ef-40de-a48a-2972777d2682
< 3.2.0
CRITICAL 9.8 The WordPress Contact Form, Drag and Drop Form Builder Plugin – Live Forms plugin for WordPress is vulnerable to gener… wordfence
1374b266-4b20-4706-a4d2-482122964693 CRITICAL 9.8 The WordPress Gallery Plugin plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and includin… wordfence
136eb400-d5cf-4b73-a8e4-9484faa81049 CRITICAL 9.8 The WPAMS - Apartment Management System for wordpress plugin for WordPress is vulnerable to arbitrary file uploads due t… wordfence
13629598-d45d-4ff5-aeb5-6ac881d25183
< 5.7.26
CRITICAL 9.8 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… wordfence
135ab17b-5b91-484a-8bec-6f77d694ae62 CRITICAL 9.8 The WPE Indoshipping for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the up… wordfence
13031db7-aeac-4d44-94f9-1cdb84781a55
< 1.3.7
CRITICAL 9.8 The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection,… wordfence
12f319df-41eb-484a-8fca-af6ae76f4179
< 1.1
CRITICAL 9.8 The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includin… wordfence
12bb4bb9-e908-43ad-8fb1-59418580f5e1
< 3.2.6
CRITICAL 9.8 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor… wordfence
129f810d-ff83-4428-9f98-6a6aa8817783
< 1.4.4
CRITICAL 9.8 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in … wordfence
1283e839-8588-4a76-9c1e-61562526166d
< 2.6.8.2
CRITICAL 9.8 The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to mis… wordfence
12660851-c899-4ec2-b40e-e62391dafdbf
< 1.25
CRITICAL 9.8 The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue.… wordfence
125277bc-5232-49bd-8f29-3aa8e0ee354b CRITICAL 9.8 The Fami WooCommerce Compare plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… wordfence
121afcc4-754c-4f4b-8b02-9b5a4a248041 CRITICAL 9.8 The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from th… wordfence
121160a3-b090-4a33-9615-fa4626631bec
< 4.0.7
CRITICAL 9.8 The Mailster - Email Newsletter Plugin for WordPress plugin for WordPress is vulnerable to Local File Inclusion in all v… wordfence
117e797a-1878-4b5f-9846-4a73b5396ece
< 1.3
CRITICAL 9.8 Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remo… wordfence
113554f9-b8f0-4bdd-be90-0093fb520022 CRITICAL 9.8 The Duplicate Page and Post plugin for WordPress is vulnerable to a developer-created backdoor in versions up to, and in… wordfence
11349bc4-b432-4225-82a4-30bc9d0057f9
< 1.5.8
CRITICAL 9.8 The Leaflet Maps Marker Pro plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up … wordfence
111c46c3-7c70-454b-8e99-1552cf0104e2 CRITICAL 9.8 The WP Front-End Repository Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… wordfence
← Prev 88 89 90 91 92 93 94 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top