ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 94 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0ae243af-619f-4405-b1e0-9b44c1869501
< 1.0.84
CRITICAL 9.8 The Ultimate Member plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the … wordfence
0a8aa964-d18c-420d-864b-9ee5cb5e2f0f CRITICAL 9.8 The Instant Chat Floating Button for WordPress Websites plugin for WordPress is vulnerable to Local File Inclusion in al… wordfence
0a4aad30-ff74-43ef-9739-225602624255
< 1.3.10
CRITICAL 9.8 The Aora theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.9. This makes i… wordfence
0a3ae696-f67d-4ed2-b307-d2f36b6f188c
< 1.4.0
CRITICAL 9.8 The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 vi… wordfence
09c59fb5-8264-4277-a821-dbfee0900f64
< 3.3.4
CRITICAL 9.8 Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 r… wordfence
09adfe7e-f154-4143-827f-957ded3ffc8f
< 1.3.8
CRITICAL 9.8 The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generat… wordfence
097b1530-64fa-45b2-85f3-c6a2311405b5 CRITICAL 9.8 The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
09679bd2-c416-4037-bfa4-d56ba862113c
< 2.6.7
CRITICAL 9.8 The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (avail… wordfence
094c5011-41f6-420b-b566-e77fd55d9011
< 1.2.2
CRITICAL 9.8 The Gmedia Photo Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… wordfence
094aa8ea-42f0-484f-80fe-a0bf3a110adc
< 3.2.3
CRITICAL 9.8 The Search & Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.… wordfence
094972e6-7e02-4060-b069-e39c8cde9331
< 3.6.0
CRITICAL 9.8 The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word… wordfence
09437329-f01a-4998-90ec-e4b2e271e896
< 2.15.0
CRITICAL 9.8 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all vers… wordfence
093058f1-c717-424f-9bd5-4838df8d20a1
< 4.2.7
CRITICAL 9.8 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali… wordfence
08efd1c4-8024-465f-9f29-02e78c4228ab
< 2.12.0
CRITICAL 9.8 The STAGGS – Product Configurator Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing … wordfence
08e9a8f1-e5ed-4af7-ab37-31bab8850dbd
< 1.6.5
CRITICAL 9.8 The Petito theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.4. This makes… wordfence
08cb8ba1-1976-438b-8e0b-0a8be08aad6c
< 5.1.3
CRITICAL 9.8 The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions … wordfence
08ca186a-2486-4a58-9c53-03e9eba13e66
< 7.6.5
CRITICAL 9.8 The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authe… wordfence
08c14611-c785-484d-9fdf-7d71c39f63df
< 0.15.2
CRITICAL 9.8 The Global Flash Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘popup.php id' parameter … wordfence
0870de2d-bca5-4d57-a07f-877a416ce0d5
< 2.10.1
CRITICAL 9.8 THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, … wordfence
086b51b5-c9f6-4b30-8fa1-4bcc005c66ab
< 3.1.9.1
CRITICAL 9.8 SQL injection vulnerability in the WPML plugin before 3.1.9.1 for WordPress allows remote attackers to execute arbitrary… wordfence
081f2603-229b-42f2-b5b1-f89d105a31d5
< 2.9.5
CRITICAL 9.8 The ListingPro Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2… wordfence
07eb71fc-6588-490d-8947-3077ec4a9045
< 3.28.30
CRITICAL 9.8 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i… wordfence
07eab536-6f20-45ec-9f9e-70ab35555db2
< 6.0.0
CRITICAL 9.8 The WappPress – Create Mobile App for any WordPress site with our Mobile App Builder in just 1 minute plugin for WordP… wordfence
07ac1921-6d3b-44b3-ad8d-66e18698c025
< 0.1.2
CRITICAL 9.8 The Note Press plugin for WordPress before 0.1.2 has a SQL injection vulnerability via the s parameter. This can be expl… wordfence
079d60c1-a15a-4d3e-b295-8c1e024b74ef
< 3.0.0
CRITICAL 9.8 The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authenticated bypass in all ve… wordfence
← Prev 91 92 93 94 95 96 97 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top