🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,762
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 28, 2026
Last Updated

41,762 vulnerabilities found (page 92 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
205a3e43-8ac6-4a0d-86d3-bb433a992e3d
< 1.9
CRITICAL 9.8 The RokIntroScroller plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… — wordfence
20188fd3-c330-4c76-912b-72731e14c450
< 1.6.0
CRITICAL 9.8 The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and… — wordfence
200f724e-7911-46d0-82c0-ffa207d8ee17
< 2.4.0
CRITICAL 9.8 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads… — wordfence
20077e55-fe75-49c7-ba3f-ccd683a3f722 CRITICAL 9.8 The Vithy theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload… — wordfence
1fa39169-1cba-43ce-aa29-adf7ce09ce75
< 1.6.0
CRITICAL 9.8 The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt… — wordfence
1f93ecf7-ba49-47f6-abe3-33e3bc6e7054
< 1.1.7
CRITICAL 9.8 Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for Wo… — wordfence
1f891b68-72c4-4f94-bd49-52576ad710f9 CRITICAL 9.8 The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing … — wordfence
1f714f97-5e1a-498a-9722-1e4bb883c5c7
< 1.2.1
CRITICAL 9.8 Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). Fixed in 1.2.6… — wordfence
1f5b4f9a-4067-4514-9027-b645921d807f
< 1.3.0
CRITICAL 9.8 Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the … — wordfence
1f4f66fd-189a-4036-8e44-c401647bc655
< 2.1.1
CRITICAL 9.8 The Medicare theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.0 via deser… — wordfence
1ef13f92-ae45-411a-b7b4-cdaf299afc8a CRITICAL 9.8 The CoSchool LMS – A complete Learning Management System to Create and Sell Your Courses Online plugin for WordPress i… — wordfence
1ec14b1e-6d1a-4451-9fce-ac064623d92f
< 1.4.0
CRITICAL 9.8 The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege… — wordfence
1ead6a38-b495-47d2-8d40-1f17e64fd1ff
< 1.8.10.2
CRITICAL 9.8 SQL injection vulnerability in the Contextual Related Posts plugin before 1.8.10.2 for WordPress allows remote attackers… — wordfence
1e8f71cc-3197-4cdb-9e3b-a544f689df2d CRITICAL 9.8 The Pathomation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … — wordfence
1e65922a-3498-4946-8415-3d922e85e46a
< 4.5.0.2
CRITICAL 9.8 The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.0.1 v… — wordfence
1e61cc33-d58e-425e-9835-4d45461edbac CRITICAL 9.8 The Nasa Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.2. This m… — wordfence
1e37e54b-9c00-4d04-9c81-791242d45d6c CRITICAL 9.8 The iDump iPhone to WordPress Photo Uploader for WordPress is vulnerable to arbitrary file uploads due to missing file t… — wordfence
1decdfd8-a2e8-49af-ade8-01d19814b6fb CRITICAL 9.8 The Flagallery-skins plugin for WordPress is vulnerable to generic SQL Injection via the ‘playlist’ parameter in all… — wordfence
1de9183c-95b9-4500-85e2-08dcee956360
< 1.0.5
CRITICAL 9.8 The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… — wordfence
1d9ffbf3-520a-4563-85e1-27c1cc544856 CRITICAL 9.8 The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it… — wordfence
1d8d393e-764c-491d-8afb-7d4f8d0c387a
< 2.1.0
CRITICAL 9.8 The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password rese… — wordfence
1d87d225-7de4-49f8-9cba-391d718af7fd CRITICAL 9.8 The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers t… — wordfence
1d7f1283-a274-49a2-8bec-da178771b13a
< 4.11.2
CRITICAL 9.8 The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … — wordfence
1d779ad1-fdbe-444c-85c5-99146a1a03d8
< 1.0.5
CRITICAL 9.8 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ima… — wordfence
1d640d8e-7730-47e1-9f01-b9656f1ebb1c
< 1.6.1
CRITICAL 9.8 The GrandPrix theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. This make… — wordfence
← Prev 89 90 91 92 93 94 95 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top