πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 96 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
05431aaa-5d8f-422c-b7ce-955a778f7f55 CRITICAL 9.8 The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive. wordfence
053bb01c-9e87-4836-ae1c-567272b21118
< 2.0.16
CRITICAL 9.8 The Registration Forms – User Profile, Custom Registration Form, Login Form, Invitation-Based Registrations plugin for… wordfence
05178bf3-3040-41aa-ba43-779376d30298
< 1.7.6
CRITICAL 9.8 The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5… wordfence
0502c622-975f-4218-8b53-efd776fe9d99
< 1.0.6
CRITICAL 9.8 The newstatpress plugin before 1.0.6 for WordPress has SQL injection related to an IMG element. wordfence
04d8b1bf-d514-4908-a30e-6ff7b8e03f82
< 1.2.2
CRITICAL 9.8 The sharebar plugin before 1.2.2 for WordPress has SQL injection via id parameter. wordfence
04bc8101-2676-4695-a498-f79be8221617
< 2.6.8
CRITICAL 9.8 The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includi… wordfence
04b7a2ba-e299-4781-8ee6-644938bf9629
< 3.4.5
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization via the api/flu… wordfence
0491b8b3-014e-4ef2-b3b6-9570063fffc5
< 3.8.3.3
CRITICAL 9.8 The Pie Register Premium plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to 3.8.3.3 (exc… wordfence
0486fca3-49d4-4edb-9b32-952a20ffa59f
< 2.4
CRITICAL 9.8 The DSK theme for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 2.4. This makes it p… wordfence
0451a7b8-7657-4b73-9ef1-cc3791349e59
< 1.1.1
CRITICAL 9.8 The Selio - Real Estate Directory theme for WordPress is vulnerable to generic SQL Injection via the β€˜is’ parameter … wordfence
04033a28-b58a-4584-926b-f43036b23247 CRITICAL 9.8 The Multi Purpose Mail Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
04003542-fd62-4587-9834-70e7fe8f08ef
< 2.0.7
CRITICAL 9.8 The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, … wordfence
03be4344-d388-4357-8a2e-c3b9c8b83017
< 1.5.6.8
CRITICAL 9.8 The e-signature plugin for WordPress is vulnerable to Remote Code Execution in versions before 1.5.6.8. This allows unau… wordfence
03b9187e-022a-48c1-a79c-c4629357de5a CRITICAL 9.8 Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contac… wordfence
038deaeb-633f-49de-92d8-e593ceb47b1e
< 1.0.5
CRITICAL 9.8 The RewardsWP – Loyalty Points & Referral Program for WooCommerce plugin for WordPress is vulnerable to Privilege Esca… wordfence
038ddfcd-093b-4234-a0b8-a3bf9a3d329f CRITICAL 9.8 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus… wordfence
0386ed09-296d-4f33-9fe0-964c0c0a9652
< 1.7.0
CRITICAL 9.8 The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation wi… wordfence
037a8b06-18be-4443-b54c-22f50c89d5b4
< 4.0.9
CRITICAL 9.8 The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues. wordfence
034ea306-148f-4a67-abac-a2c6a280745c CRITICAL 9.8 The WP Vehicle Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.… wordfence
033e8326-38ed-4d36-8a29-06f9c8a5e808
< 2.0.3.2
CRITICAL 9.8 The Wholesale Lead Capture Plugin for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all vers… wordfence
030b26ac-344f-4919-9d2d-b85e5e1599f6
< 2.8.6
CRITICAL 9.8 The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,… wordfence
02fe4a33-d059-461c-a03f-b7306ce6193f
< 5
CRITICAL 9.8 The GeoPlaces 4 Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the … wordfence
02d6e9c3-f040-4a41-a803-4bbe5f86c29b
< 5.4.12
CRITICAL 9.8 The Woffice CRM theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.10. … wordfence
02cf0e1a-bd12-44b1-9bc5-1a5ec332b000
< 1.2.0
CRITICAL 9.8 The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.13. This is du… wordfence
02bb12db-0bc9-4c13-918f-1f90b500c165
< 1.4.26
CRITICAL 9.8 The PropertyHive plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.4.25 vi… wordfence
← Prev 93 94 95 96 97 98 99 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top