πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 97 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
02b75034-8db1-465b-837e-014e2c2e8b4d
< 2.8.0
CRITICAL 9.8 The Asgaros Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.7.2… wordfence
02998107-9415-433a-8c64-5838324bdcc3 CRITICAL 9.8 The Essential Real Estate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5… wordfence
0254726d-ce5b-454c-ab8b-d778beb375d4 CRITICAL 9.8 The Evon theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.4. This makes it … wordfence
023910d0-c2eb-41cd-9d42-606c4cbb8059
< 1.3.3.3
CRITICAL 9.8 The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Uploa… wordfence
022f6239-67f2-4680-aeed-34c98c953bea
< 1.0
CRITICAL 9.8 The BJ Lazy Load plugin v0.7.5 for WordPress has Remote File Inclusion vulnerability via TimThumb. wordfence
0209c6ab-cc49-4929-851d-b12c5decf975
< 7.0
CRITICAL 9.8 The AR For WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
01f4318f-b56b-4a34-987b-05edeee5da69
< 2.2.4
CRITICAL 9.8 The wpForo Forum plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.2.3.… wordfence
0152bcc9-6d24-4475-848d-71fe88aa7e2a
< 3.30.3
CRITICAL 9.8 The Leyka plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.30.2. This allo… wordfence
014f1aae-10a0-4bc8-b176-dbdad94a6ad8
< 5.0.5
CRITICAL 9.8 The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data befor… wordfence
01427553-bc1d-4927-9110-0facd301d976 CRITICAL 9.8 The Quick Learn plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.1 via d… wordfence
0111a73e-3d5a-4dd5-8974-dc43aafb5050
< 4.9.9
CRITICAL 9.8 The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in all versions up to 4.9.9 (… wordfence
010300f9-adef-4958-ac77-6ff981833e9e CRITICAL 9.8 The Blaze Slide Show plugin for Wordpress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
010183f3-d614-4fe7-aa70-56d6b3fc5ddc CRITICAL 9.8 The WizShop plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.2. This mak… wordfence
00ae6b57-6ce2-4e39-91c9-7b2c5b38124b CRITICAL 9.8 The is-human plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.2 via… wordfence
005fa621-3c49-4c23-add5-d6b7a9110055
< 2.8.3
CRITICAL 9.8 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
005d1abc-761d-4f9a-bc21-aad63e8efd66
< 1.8
CRITICAL 9.8 The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7… wordfence
ffaf7a75-de27-4361-ba04-ff17151b7eb5 CRITICAL 9.6 The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its setti… wordfence
fc9dfe96-2d43-4b7b-a91a-87cdaaab8e49
< 1.7.2
CRITICAL 9.6 The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX act… wordfence
f908837d-2bba-45db-b005-f685a33cd71e CRITICAL 9.6 The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could a… wordfence
f8bcf51a-36ee-4d4d-b9d6-d9db0dafd791
< 2.32.11
CRITICAL 9.6 The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arb… wordfence
f4703ca7-0677-4128-b9b7-31132ff1804d
< 4.2
CRITICAL 9.6 The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to CSV Injection in versions up … wordfence
ef5028a0-6a5a-40ad-92df-ffc988cad389
< 4.09.05
CRITICAL 9.6 The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img… wordfence
d8e23501-9fc4-484b-b308-a9c51494bc9d CRITICAL 9.6 The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could … wordfence
cacd31bd-ccc6-49fa-89f1-09f3c5cd9072
< 4.4.5
CRITICAL 9.6 The Captcha plugin for WordPress contained a backdoor that injected SEO spam into unsuspecting users WordPress sites in … wordfence
c8abcc7b-6c68-4fc8-81af-e88624e417dd
< 5.1.0
CRITICAL 9.6 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… wordfence
← Prev 94 95 96 97 98 99 100 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top