πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 96 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
14a1b8af-bd32-4245-92d6-549cae68c626
< 6.9.0
CRITICAL 9.8 The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to w… — wordfence
14981949-271c-4f98-a6a1-b00619f1436d
< 1.1
CRITICAL 9.8 The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0… — wordfence
146c8783-ba59-41da-9e95-7401865b7b8c
< 2.5.17
CRITICAL 9.8 SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote atta… — wordfence
144df910-67d2-4e3b-9ccf-04ebd5d1bf8b
< 1.5.4.9
CRITICAL 9.8 SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allo… — wordfence
13b4efa1-3f52-476c-80fe-b36ccb62a24b
< 3.0.5
CRITICAL 9.8 The Podcasting Plugin by TSG plugin for WordPress is vulnerable to Remote File Inclusion of media files in versions up t… — wordfence
13b2fb59-35ef-40de-a48a-2972777d2682
< 3.2.0
CRITICAL 9.8 The WordPress Contact Form, Drag and Drop Form Builder Plugin – Live Forms plugin for WordPress is vulnerable to gener… — wordfence
1374b266-4b20-4706-a4d2-482122964693 CRITICAL 9.8 The WordPress Gallery Plugin plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and includin… — wordfence
136eb400-d5cf-4b73-a8e4-9484faa81049 CRITICAL 9.8 The WPAMS - Apartment Management System for wordpress plugin for WordPress is vulnerable to arbitrary file uploads due t… — wordfence
13629598-d45d-4ff5-aeb5-6ac881d25183
< 5.7.26
CRITICAL 9.8 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… — wordfence
135ab17b-5b91-484a-8bec-6f77d694ae62 CRITICAL 9.8 The WPE Indoshipping for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the up… — wordfence
13031db7-aeac-4d44-94f9-1cdb84781a55
< 1.3.7
CRITICAL 9.8 The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection,… — wordfence
12f319df-41eb-484a-8fca-af6ae76f4179
< 1.1
CRITICAL 9.8 The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includin… — wordfence
12bb4bb9-e908-43ad-8fb1-59418580f5e1
< 3.2.6
CRITICAL 9.8 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor… — wordfence
129f810d-ff83-4428-9f98-6a6aa8817783
< 1.4.4
CRITICAL 9.8 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in … — wordfence
1283e839-8588-4a76-9c1e-61562526166d
< 2.6.8.2
CRITICAL 9.8 The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to mis… — wordfence
12660851-c899-4ec2-b40e-e62391dafdbf
< 1.25
CRITICAL 9.8 The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue.… — wordfence
125277bc-5232-49bd-8f29-3aa8e0ee354b CRITICAL 9.8 The Fami WooCommerce Compare plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… — wordfence
121afcc4-754c-4f4b-8b02-9b5a4a248041 CRITICAL 9.8 The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from th… — wordfence
121160a3-b090-4a33-9615-fa4626631bec
< 4.0.7
CRITICAL 9.8 The Mailster - Email Newsletter Plugin for WordPress plugin for WordPress is vulnerable to Local File Inclusion in all v… — wordfence
11f367a0-3a1a-474b-8dae-b3b0f942574a
< 3.6.5.2
CRITICAL 9.8 The JetFormBuilder β€” Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Remote Code Execution in all ve… — wordfence
117e797a-1878-4b5f-9846-4a73b5396ece
< 1.3
CRITICAL 9.8 Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remo… — wordfence
113554f9-b8f0-4bdd-be90-0093fb520022 CRITICAL 9.8 The Duplicate Page and Post plugin for WordPress is vulnerable to a developer-created backdoor in versions up to, and in… — wordfence
11349bc4-b432-4225-82a4-30bc9d0057f9
< 1.5.8
CRITICAL 9.8 The Leaflet Maps Marker Pro plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up … — wordfence
111c46c3-7c70-454b-8e99-1552cf0104e2 CRITICAL 9.8 The WP Front-End Repository Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… — wordfence
110e888d-69fc-4682-b908-2b62288c5227
< 2.2.1
CRITICAL 9.8 The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in… — wordfence
← Prev 93 94 95 96 97 98 99 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top