🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 93 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1d54bd25-148f-4e9a-bd31-77b52efd5499 CRITICAL 9.8 The Wp NssUser Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including,… — wordfence
1d2b78e0-1b82-4074-8051-e44dcfe3ac51 CRITICAL 9.8 The Compute Links plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 1.2.… — wordfence
1cefe584-c1b0-418c-bade-ca4092807b1b
< 2.6
CRITICAL 9.8 The duplicate-post plugin before 2.6 for WordPress has SQL injection. — wordfence
1cc1727e-92a6-484d-bdd1-d79aec534df5 CRITICAL 9.8 The Product Lister for eBay plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including,… — wordfence
1cbd298c-cba3-4986-b44c-a75b005b4340
< 0.9.7b
CRITICAL 9.8 The The Hacker's Diet plugin for WordPress is vulnerable to SQL Injection via the 'user' parameter in all versions up to… — wordfence
1cab1bef-c8c5-45ee-921e-0d01736e74c6 CRITICAL 9.8 The postMash – custom post order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… — wordfence
1c7c0c35-5f44-488f-9fe1-269ea4a73854
< 4.10.8
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up… — wordfence
1c6bf45b-b02d-43bb-b682-7f1ae994e1d3
< 1.7
CRITICAL 9.8 The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions … — wordfence
1c648de5-14b3-4c7f-a1c2-46d91b56b0ff
< 1.11
CRITICAL 9.8 PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allow… — wordfence
1c0c6a45-2c4a-4a23-84e6-7a9759796824
< 4.9.56
CRITICAL 9.8 The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnera… — wordfence
1bd44471-1a9c-4465-a52a-be64d51e7ea1 CRITICAL 9.8 The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.… — wordfence
1bbe01b8-24ed-4e1e-bafc-0f4dea96c1f3
< 2.3.4
CRITICAL 9.8 The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.… — wordfence
1bb4674e-71e4-43db-ad9e-36ab15432149
< 4.6.9
CRITICAL 9.8 The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, res… — wordfence
1ba55302-b38f-4932-bbba-cdd517380ad7
< 6.9.5
CRITICAL 9.8 WordPress Core is vulnerable to Remote Code Execution in all versions 6.9 to 7.0.1 via the REST API batch request endpoi… — wordfence
1b94583f-405e-4fd3-849e-33563b72f698
< 7.2.3
CRITICAL 9.8 The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data du… — wordfence
1b5a0c87-59b0-4da4-8949-0957f8e1b479 CRITICAL 9.8 The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the… — wordfence
1b4acf11-114a-4e97-89cd-1d387f14a730 CRITICAL 9.8 The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ par… — wordfence
1b4630f7-74db-46c4-bf86-f1ff64be3463
< 1.11.10.8
CRITICAL 9.8 The BERTHA AI. Your AI co-pilot for WordPress and Chrome plugin for WordPress is vulnerable to arbitrary file uploads du… — wordfence
1b097ab2-7675-4409-b22a-ad70cee35ab1
< 2.5.7.1
CRITICAL 9.8 The GamiPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.7 due to insuffi… — wordfence
1ad38d18-689c-41ab-9e33-fccbf6791cdb CRITICAL 9.8 Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0 in /zen-mobile-app-native/server/images.php f… — wordfence
1ac218f6-0bfa-480c-9159-d75a027022ba
< 17.8
CRITICAL 9.8 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… — wordfence
1aac7677-53f4-4944-9bdc-7e07b09c6c13
< 1.5
CRITICAL 9.8 The ND Restaurant Reservations plugin before 1.5 for WordPress is vulnerable to unauthenticated option changes via the n… — wordfence
1a97e50f-c3ce-4e25-80c5-3de5e45431fb CRITICAL 9.8 The Personal QR Message plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 1.… — wordfence
1a74252c-1385-4ee7-aeaa-f0476336b1e6 CRITICAL 9.8 The Umberto theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.8 via deseri… — wordfence
1a4cc739-0563-4ca2-931d-818a0c285257
< 1.5.5
CRITICAL 9.8 SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attack… — wordfence
← Prev 90 91 92 93 94 95 96 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top