πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 95 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
073a3b48-7c21-4511-a8e4-3443ef05fd0b CRITICAL 9.8 The MainWP Broken Link Checker plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up… wordfence
0728e7ac-2091-41de-90a0-e231c4b99ab0
< 1.3.2
CRITICAL 9.8 The WooFramework, used for all WooThemes for WordPress, is vulnerable to Remote Code Execution in versions up to, and in… wordfence
071195d6-3452-4241-a8d3-92efc84e4850
< 5.1.17
CRITICAL 9.8 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… wordfence
07067eb5-d15e-4342-914f-5e2a08ea8bb4
< 4.4.0
CRITICAL 9.8 The WP Live Chat Support plugin for WordPress is vulnerable to blind SQL Injection via the 'cid' and 'status' parameter … wordfence
06eaf624-aedf-453d-8457-d03a572fac0d
< 3.1.4
CRITICAL 9.8 The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
06e90f64-f64e-4871-9106-1d7af02f13d2 CRITICAL 9.8 The Nuance theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'VALUM… wordfence
06dfc3da-6f61-433c-a1e1-48749b654fcd
< 2.8.1
CRITICAL 9.8 The Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… wordfence
06b92517-5431-43ed-ad3b-80bfd0981b93
< 4.0.7
CRITICAL 9.8 The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues. wordfence
06a7ff0b-ec6b-490c-9bb0-fbb5c1c337c4
< 3.19.4
CRITICAL 9.8 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… wordfence
068da172-629d-422a-bcd5-1b73af2a5933
< 1.1.8
CRITICAL 9.8 The Recip.ly Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
068d9502-705e-45dc-a7fb-e75866226fdd CRITICAL 9.8 The Videos sync PDF plugin for WordPress is vulnerable to Local File Inclusion in versions up to an equal to 1.7.4 via t… wordfence
06881386-3c92-426b-948d-58e8a8bee624 CRITICAL 9.8 The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid… wordfence
0685abc6-eac6-46c5-87ae-52e2af9301c2 CRITICAL 9.8 The WP REST API FNS Plugin plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and inclu… wordfence
06382aab-8a92-43a2-a4fa-7bbd21967326
< 2.2.3
CRITICAL 9.8 The miniOrange Discord Integration plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inc… wordfence
063826cc-7ff3-4869-9831-f6a4a4bbe74c
< 18.5.10
CRITICAL 9.8 The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local F… wordfence
061f022b-b922-4499-bb34-8ea91ba5ace3 CRITICAL 9.8 The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via accoun… wordfence
05ea5a3c-084a-458f-b0b1-8a9b82e4656a CRITICAL 9.8 The Comment Rating plugin for WordPress is vulnerable to generic SQL Injection via the 'ck_ips' parameter in versions up… wordfence
05d32a0f-b299-4dfd-8d92-4bd0a9872a0b CRITICAL 9.8 The ABC APP CREATOR plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1… wordfence
05c68377-feb6-442d-a3a0-1fbc246c7cbf
< 3.10
CRITICAL 9.8 The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in vers… wordfence
05c40628-b8fc-48ff-8819-c0955d69fce0
< 4.8.0
CRITICAL 9.8 The Pipdig Power Pack(p3) plugin for WordPress is contained a backdoor in versions before 4.8.0. Obfuscated code was pre… wordfence
05a81b0e-2d25-44b5-b791-5b2aed94bbab CRITICAL 9.8 The MyFTP plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 1.1 due to insuf… wordfence
0578f4d1-5953-4fbe-8bc3-0569bee57a1a
< 2.7.2
CRITICAL 9.8 The Houzez theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.7.1. This is du… wordfence
05776ec2-b432-40f6-bd75-4e6ec103c497 CRITICAL 9.8 The Arlo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.0.3. This makes i… wordfence
056d26da-6e43-4cc6-b2fd-13a5947a814e CRITICAL 9.8 The SAICO theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the php.ph… wordfence
05544f69-bc9b-4270-80c9-96afe4793cb6
< 1.6.2
CRITICAL 9.8 PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordP… wordfence
← Prev 92 93 94 95 96 97 98 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top