πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 93 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0e556ca2-1b83-4589-bff8-64323eb594e7
< 1.8.4
CRITICAL 9.8 The Coupon Referral Program plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includ… wordfence
0e4588d1-f21e-48ba-a8cb-d18c421f000a
< 3.1.15
CRITICAL 9.8 The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and incl… wordfence
0e2774fc-f028-436c-a8af-3c17378b9743 CRITICAL 9.8 The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Pri… wordfence
0df7f413-2631-46d9-8c0b-d66f05a02c01
< 24.0.8
CRITICAL 9.8 The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up t… wordfence
0dc5c05d-51b7-4aee-bb4e-366ded45c4d8
< 5.8013
CRITICAL 9.8 The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … wordfence
0db85f84-04e9-42eb-a16b-96554fbfd186
< 1.2.22
CRITICAL 9.8 The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. T… wordfence
0d806853-48c7-4c1c-9a9f-37d493695682
< 1.5.4
CRITICAL 9.8 Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress al… wordfence
0d517094-8038-4951-b16a-db7bf2c31851
< 2.0.4
CRITICAL 9.8 The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plug… wordfence
0d4e3560-2208-4122-812e-0c506fe45126
< 2.1.1
CRITICAL 9.8 The Autoptimize plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.0. This… wordfence
0d2136e8-6769-4493-859b-dec8803be285 CRITICAL 9.8 The DyaPress ERP/CRM plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 18.0.2… wordfence
0d1a9adb-ade4-4ac5-ad68-1354a4418db0 CRITICAL 9.8 The WordPress eCommerce – ScottCart plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,… wordfence
0c6c26d5-d4a1-49d7-890a-71d31b7afa89
< 2.0.5
CRITICAL 9.8 The Plug your WooCommerce into the largest catalog of customized print products from Helloprint plugin for WordPress is … wordfence
0c43b078-44e0-43ed-9762-b65575443576 CRITICAL 9.8 The Build App Online plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.23… wordfence
0c3fe714-94c9-47ea-b073-a082e4713977
< 1.4
CRITICAL 9.8 The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking. wordfence
0c11668c-6dc3-4539-b2be-bf6528bed73e
< 1.2.0
CRITICAL 9.8 The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeov… wordfence
0bb11092-4367-4f51-9dd7-22fbd655a03f
< 1.0.7
CRITICAL 9.8 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ima… wordfence
0ba5da2b-6944-4243-a4f2-0f887abf7a66 CRITICAL 9.8 The WP eCommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'cart_contents' parameter … wordfence
0b9e18b2-b49a-4833-8f3c-1b95477325d5 CRITICAL 9.8 The CraftXtore theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7. This mak… wordfence
0b870d35-7e10-4fb5-8c3b-2bf299d1f3d5
< 2.0.1
CRITICAL 9.8 The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, … wordfence
0b75c681-ecd2-4603-8819-07b2e9b8d547 CRITICAL 9.8 The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This all… wordfence
0b606ded-ab50-486a-9337-97ee9f452f12
< 3.3.27
CRITICAL 9.8 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… wordfence
0b52cc2a-c511-4801-8a95-f90d8d980c85
< 2.8.2
CRITICAL 9.8 The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id paramet… wordfence
0b4b0cd0-dcc2-4790-8aeb-a304088dea3c
< 0.36
CRITICAL 9.8 The Xerte Online plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via th… wordfence
0b238414-b8fa-4251-8ad4-1bb693b90a27
< 1.2.1
CRITICAL 9.8 The Magn WP Drag And Drop Media Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil… wordfence
0b2051e8-3195-498a-9d76-8645fd8476c1
< 2.1.47
CRITICAL 9.8 The Blocksy Companion Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi… wordfence
← Prev 90 91 92 93 94 95 96 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top