🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 99 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0b4b0cd0-dcc2-4790-8aeb-a304088dea3c
< 0.36
CRITICAL 9.8 The Xerte Online plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via th… — wordfence
0b238414-b8fa-4251-8ad4-1bb693b90a27
< 1.2.1
CRITICAL 9.8 The Magn WP Drag And Drop Media Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil… — wordfence
0b2051e8-3195-498a-9d76-8645fd8476c1
< 2.1.47
CRITICAL 9.8 The Blocksy Companion Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi… — wordfence
0ae243af-619f-4405-b1e0-9b44c1869501
< 1.0.84
CRITICAL 9.8 The Ultimate Member plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the … — wordfence
0a8aa964-d18c-420d-864b-9ee5cb5e2f0f CRITICAL 9.8 The Instant Chat Floating Button for WordPress Websites plugin for WordPress is vulnerable to Local File Inclusion in al… — wordfence
0a4aad30-ff74-43ef-9739-225602624255
< 1.3.10
CRITICAL 9.8 The Aora theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.9. This makes i… — wordfence
0a3ae696-f67d-4ed2-b307-d2f36b6f188c
< 1.4.0
CRITICAL 9.8 The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 vi… — wordfence
0a32b02f-db40-42fe-b46c-4a5f2bc9ba09
< 4.2.2
CRITICAL 9.8 The Elementor Pro plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and includi… — wordfence
09c59fb5-8264-4277-a821-dbfee0900f64
< 3.3.4
CRITICAL 9.8 Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 r… — wordfence
09adfe7e-f154-4143-827f-957ded3ffc8f
< 1.3.8
CRITICAL 9.8 The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generat… — wordfence
097b1530-64fa-45b2-85f3-c6a2311405b5 CRITICAL 9.8 The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… — wordfence
09679bd2-c416-4037-bfa4-d56ba862113c
< 2.6.7
CRITICAL 9.8 The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (avail… — wordfence
0951bc88-aa4e-4584-8203-9e02af322494
< 3.12.0
CRITICAL 9.8 The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and incl… — wordfence
094c5011-41f6-420b-b566-e77fd55d9011
< 1.2.2
CRITICAL 9.8 The Gmedia Photo Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… — wordfence
094aa8ea-42f0-484f-80fe-a0bf3a110adc
< 3.2.3
CRITICAL 9.8 The Search & Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.… — wordfence
094972e6-7e02-4060-b069-e39c8cde9331
< 3.6.0
CRITICAL 9.8 The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word… — wordfence
09437329-f01a-4998-90ec-e4b2e271e896
< 2.15.0
CRITICAL 9.8 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all vers… — wordfence
093058f1-c717-424f-9bd5-4838df8d20a1
< 4.2.7
CRITICAL 9.8 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali… — wordfence
08efd1c4-8024-465f-9f29-02e78c4228ab
< 2.12.0
CRITICAL 9.8 The STAGGS – Product Configurator Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing … — wordfence
08e9a8f1-e5ed-4af7-ab37-31bab8850dbd
< 1.6.5
CRITICAL 9.8 The Petito theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.4. This makes… — wordfence
08cb8ba1-1976-438b-8e0b-0a8be08aad6c
< 5.1.3
CRITICAL 9.8 The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions … — wordfence
08ca186a-2486-4a58-9c53-03e9eba13e66
< 7.6.5
CRITICAL 9.8 The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authe… — wordfence
08c14611-c785-484d-9fdf-7d71c39f63df
< 0.15.2
CRITICAL 9.8 The Global Flash Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘popup.php id' parameter … — wordfence
0870de2d-bca5-4d57-a07f-877a416ce0d5
< 2.10.1
CRITICAL 9.8 THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, … — wordfence
086b51b5-c9f6-4b30-8fa1-4bcc005c66ab
< 3.1.9.1
CRITICAL 9.8 SQL injection vulnerability in the WPML plugin before 3.1.9.1 for WordPress allows remote attackers to execute arbitrary… — wordfence
← Prev 96 97 98 99 100 101 102 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top