🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 92 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
10b7a88f-ce46-42aa-ab5a-81f38288a659
< 1.7
CRITICAL 9.8 The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions … wordfence
109b4947-f690-4158-9e6a-00f2005a6938 CRITICAL 9.8 The Adminer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the adminer_… wordfence
1069434a-b8cb-4e29-995d-f31b18d1843f
< 1.3.1
CRITICAL 9.8 Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.3 for WordPress allows remote at… wordfence
104badec-6e6e-44bb-936b-d135dd80890d
< 6.4
CRITICAL 9.8 The LiteSpeed Cache plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.3… wordfence
102ab838-9011-4da6-bc24-179be1328bcc
< 4.1
CRITICAL 9.8 SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme up to and including version 4.0 for WordPress all… wordfence
102223a1-07f5-485b-a6af-49cf316d9797
< 3.2.33
CRITICAL 9.8 The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
0ff16836-b333-4f2c-b998-04c95d3be9c2
< 1.5.8
CRITICAL 9.8 The Formality plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.7. This m… wordfence
0fcb1237-5d96-47f6-9f0c-3a0fd72ca91f
< 3.0
CRITICAL 9.8 The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload. wordfence
0fc781bc-d0e6-4fce-95aa-ff34caa072da CRITICAL 9.8 The Valen - Sport, Fashion WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in vers… wordfence
0fae8440-ce36-45ba-bed2-af30162e4c1b CRITICAL 9.8 The Subscribe to Category plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.4 du… wordfence
0f9b6979-2662-4d2f-9656-b880dd80832c
< 13.5.6
CRITICAL 9.8 The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… wordfence
0f6d3435-61b9-4986-9da9-b58d1bbc2271
< 3.9.7
CRITICAL 9.8 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… wordfence
0f54574f-e640-4cfb-b03e-fd23f3bd574b
< 3.9.1
CRITICAL 9.8 The Funnel Builder by FunnelKit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… wordfence
0f3b3c1a-1d45-4e2f-854a-171fe759257b
< 1.5.7
CRITICAL 9.8 The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication … wordfence
0f36a924-6a68-40ff-bf1a-9ebcad1c2fc6
< 2.9.42.1
CRITICAL 9.8 Versions 2.9.36 to 2.9.42 of the Ninja Forms plugin contain an unauthenticated file upload vulnerability, allowing guest… wordfence
0f35cc8b-11be-4664-be48-12a8db872d66
< 9.0.1
CRITICAL 9.8 The Title Experiments Free Plugin for WordPress is vulnerable to blind SQL Injection via the ‘wpex_titles' AJAX action… wordfence
0f23aa0e-eb1f-4310-9615-d67eb39389fe
< 2.9.2
CRITICAL 9.8 The Welcart e-Commerce for WordPress is vulnerable to SQL Injection via the ‘changeSort’ and 'switch' parameters in … wordfence
0f13b2dd-4832-4646-828c-ba2df1eb7d33
< 4.0.1
CRITICAL 9.8 The plugin WP OAuth Server for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.4.… wordfence
0f0051d5-b236-420c-ae65-14610d05c6d1
< 13.1.6
CRITICAL 9.8 The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t… wordfence
0ee60943-b583-4a99-8e62-846b380c98aa
< 1.8.1.15
CRITICAL 9.8 The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulne… wordfence
0ee3b389-60c9-4f8e-9428-a71a6d9b20aa
< 2.0.7
CRITICAL 9.8 The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input … wordfence
0eae9c5a-8a11-4293-a7e1-2c5d77c75284
< 1.15.13
CRITICAL 9.8 The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic be… wordfence
0e630401-0409-443c-944d-553a372d150d
< 1.1
CRITICAL 9.8 The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php. wordfence
0e61c98d-a6f4-4ac0-b9f9-2b936c030413 CRITICAL 9.8 The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an… wordfence
0e5617a2-5670-4d98-a36b-942f71634642
< 3.1.2
CRITICAL 9.8 The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress i… wordfence
← Prev 89 90 91 92 93 94 95 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top