πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 98 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0e556ca2-1b83-4589-bff8-64323eb594e7
< 1.8.4
CRITICAL 9.8 The Coupon Referral Program plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includ… — wordfence
0e4588d1-f21e-48ba-a8cb-d18c421f000a
< 3.1.15
CRITICAL 9.8 The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and incl… — wordfence
0e2774fc-f028-436c-a8af-3c17378b9743 CRITICAL 9.8 The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Pri… — wordfence
0df7f413-2631-46d9-8c0b-d66f05a02c01
< 24.0.8
CRITICAL 9.8 The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up t… — wordfence
0dc5c05d-51b7-4aee-bb4e-366ded45c4d8
< 5.8013
CRITICAL 9.8 The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … — wordfence
0db85f84-04e9-42eb-a16b-96554fbfd186
< 1.2.22
CRITICAL 9.8 The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. T… — wordfence
0d806853-48c7-4c1c-9a9f-37d493695682
< 1.5.4
CRITICAL 9.8 Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress al… — wordfence
0d517094-8038-4951-b16a-db7bf2c31851
< 2.0.4
CRITICAL 9.8 The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plug… — wordfence
0d4e3560-2208-4122-812e-0c506fe45126
< 2.1.1
CRITICAL 9.8 The Autoptimize plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.0. This… — wordfence
0d2136e8-6769-4493-859b-dec8803be285 CRITICAL 9.8 The DyaPress ERP/CRM plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 18.0.2… — wordfence
0d1a9adb-ade4-4ac5-ad68-1354a4418db0 CRITICAL 9.8 The WordPress eCommerce – ScottCart plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,… — wordfence
0cdd5562-8755-4ca3-9c16-a5b364f8408b
< 2.3.1.1
CRITICAL 9.8 The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1… — wordfence
0c6c26d5-d4a1-49d7-890a-71d31b7afa89
< 2.0.5
CRITICAL 9.8 The Plug your WooCommerce into the largest catalog of customized print products from Helloprint plugin for WordPress is … — wordfence
0c43b078-44e0-43ed-9762-b65575443576 CRITICAL 9.8 The Build App Online plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.23… — wordfence
0c3fe714-94c9-47ea-b073-a082e4713977
< 1.4
CRITICAL 9.8 The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking. — wordfence
0c3ecf70-544f-49c1-a943-86df89685b58 CRITICAL 9.8 The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due … — wordfence
0c2266b8-cc23-46de-bc80-09e3d6294854
< 9.6.3
CRITICAL 9.8 The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Es… — wordfence
0c11668c-6dc3-4539-b2be-bf6528bed73e
< 1.2.0
CRITICAL 9.8 The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeov… — wordfence
0bb11092-4367-4f51-9dd7-22fbd655a03f
< 1.0.7
CRITICAL 9.8 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ima… — wordfence
0ba5da2b-6944-4243-a4f2-0f887abf7a66 CRITICAL 9.8 The WP eCommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'cart_contents' parameter … — wordfence
0b9e18b2-b49a-4833-8f3c-1b95477325d5 CRITICAL 9.8 The CraftXtore theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7. This mak… — wordfence
0b870d35-7e10-4fb5-8c3b-2bf299d1f3d5
< 2.0.1
CRITICAL 9.8 The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, … — wordfence
0b75c681-ecd2-4603-8819-07b2e9b8d547 CRITICAL 9.8 The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This all… — wordfence
0b606ded-ab50-486a-9337-97ee9f452f12
< 3.3.27
CRITICAL 9.8 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… — wordfence
0b52cc2a-c511-4801-8a95-f90d8d980c85
< 2.8.2
CRITICAL 9.8 The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id paramet… — wordfence
← Prev 95 96 97 98 99 100 101 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top