🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 95 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1814537d-8307-4d1f-86c8-801519172be5
< 1.7
CRITICAL 9.8 The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missi… — wordfence
17dcacaf-0e2a-4bef-b944-fb7e43d25777
< 2.7.3
CRITICAL 9.8 The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' para… — wordfence
17d8e2e9-5e3f-433b-be1a-6ea765eba547
< 4.15.0
CRITICAL 9.8 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication by… — wordfence
17ccf3f5-ac71-4827-bf11-9a5199f8752e CRITICAL 9.8 The AJAX Random Posts plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.3.3… — wordfence
17cc137e-da04-42ea-9336-24c4e0b9264a CRITICAL 9.8 The Devexhub Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… — wordfence
1789b78a-4733-40b9-b28f-f63aeb4c0f0b
< 2.10.0
CRITICAL 9.8 The TI WooCommerce Wishlist plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… — wordfence
178911d9-0552-4f44-aae5-06fc9734cfac
< 5.9.6
CRITICAL 9.8 The Event post plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.9.5 vi… — wordfence
17641096-1c7f-43f7-90d6-14c368c95d72 CRITICAL 9.8 The Advanced Personalization plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… — wordfence
16e3ca1b-817d-4f03-92ae-346a56271c47
< 3.2.0
CRITICAL 9.8 A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign… — wordfence
16c0a3b7-25b0-457e-b883-a780bc6a29a7 CRITICAL 9.8 The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter… — wordfence
16bce38a-07fa-43b7-aacb-6c932c3d0987
< 7.7.2
CRITICAL 9.8 The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using … — wordfence
16af4d96-e7e0-4b13-90a5-ddf62909271a CRITICAL 9.8 The Contus Video Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… — wordfence
169d06e1-055b-422a-a466-155ec43e0dbb
< 6.8
CRITICAL 9.8 The Simple User Registration plugin for WordPress is vulnerable to privilege escalation due to a missing capability chec… — wordfence
167436b7-3d2b-46fc-a1bc-2bcfd899182e
< 4.7.6
CRITICAL 9.8 The Noo JobMonster theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7.5… — wordfence
1672e8fb-900b-4c2a-b9fd-e64dbb1046af CRITICAL 9.8 The user files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… — wordfence
162a9203-d169-4d96-9839-110f6a9e4ad3
< 1.5.3
CRITICAL 9.8 The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the… — wordfence
15fecefa-f1f1-47f3-8ad7-ec7772ecafc4 CRITICAL 9.8 Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 a… — wordfence
15deb0db-5a13-4018-88e5-5f5cb61bd495
< 1.2
CRITICAL 9.8 The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter. — wordfence
159304a1-b015-44cd-9540-88b3e306dcc8
< 1.5.19.1
CRITICAL 9.8 The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,… — wordfence
1560b740-4018-4b08-9399-2fc87e16ea7b
< 1.1.1
CRITICAL 9.8 The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling. — wordfence
155e3de1-e115-4683-bb4d-a0c5667dc3d3
< 3.3.0
CRITICAL 9.8 The WP Post Author plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.2.3. T… — wordfence
1540bf3e-2928-476c-8e5b-241b80dd699f
< 4.3.7
CRITICAL 9.8 The RealHomes theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.3.6. Thi… — wordfence
153e435b-9986-4242-a89b-12e8f1552803
< 1.0.1
CRITICAL 9.8 The Zendrop – Global Dropshipping plugin for WordPress is vulnerable to generic SQL Injection via the setMetaData func… — wordfence
14f86410-a21c-43ee-8d78-6fcce3a5b99b CRITICAL 9.8 The Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '/u… — wordfence
14d48a81-c6b5-415f-8c82-5fd40b2e790a
< 1.7.0
CRITICAL 9.8 A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successfu… — wordfence
← Prev 92 93 94 95 96 97 98 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top