πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1021 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2214264d-0f3e-455b-9420-c6a1e0d7562c
< 2.10.6
MEDIUM 5.8 The Simple Job Board plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
1f2cfb14-1076-492f-8a1b-ae04b47dc6fa
< 2.4.6
MEDIUM 5.8 The Chatbot with ChatGPT WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca… wordfence
149eb7ef-be96-442e-925e-01d8d76e3a1a
< 3.7.32
MEDIUM 5.8 In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in t… wordfence
10b9d703-de9d-472a-bdfb-bc9a41bf375e
< 6.30.16
MEDIUM 5.8 The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request F… wordfence
046f1f8d-9e87-4ede-bcb8-56614a1f3235
< 1.5.5
MEDIUM 5.8 wordfence
035ada56-541d-47b3-8348-3401d94bb509
< 3.1.76
MEDIUM 5.8 The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, … wordfence
009a9210-531c-4b6c-83b6-8c97a4f492bd
< 2.5
MEDIUM 5.8 The Contact Form 7 plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.4. This i… wordfence
e9caf6a8-d7f6-4686-889a-79ba9cf911c4 MEDIUM 5.7 The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admi… wordfence
bc6a8c0e-1136-41ff-bfc2-450434aa6326
< 3.7.34
MEDIUM 5.7 In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external… wordfence
baae8fb9-b87c-4f61-88da-871c4c83615b
< 6.0.10
MEDIUM 5.7 The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for … wordfence
a68f024d-b80d-4e6c-8420-5e0dde87d8f0
< 2.7.0
MEDIUM 5.7 The ALO EasyMail Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
80b3c2d3-b8dc-429f-b2d7-6a697ad47a9a
< 2.1.2
MEDIUM 5.7 The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq … wordfence
659ef2e8-589c-4901-88ce-1d674c056ece
< 1.6.9
MEDIUM 5.7 The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vul… wordfence
585a7332-b063-463c-8077-68a860e14df2
< 1.6.1
MEDIUM 5.7 The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate … wordfence
19e6bd3b-8d03-4617-8be2-3cdaeb85fac0
< 1.8.1
MEDIUM 5.7 The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most … wordfence
c929a742-6481-40a0-94b5-76ddb8494896
< 3.8.3
MEDIUM 5.6 The Clerk plugin for WordPress is vulnerable to Authorization Bypass via Insufficient Validation in versions up to, and … wordfence
bf04f458-7900-4dd3-84fb-169b74db97ab
< 2.1.6.3
MEDIUM 5.6 The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass… wordfence
b43371a6-bcb5-4418-b5a5-85879775010c
< 4.3.4
MEDIUM 5.6 The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to limited SQL Inj… wordfence
8e38553d-5dba-4c84-95f7-43420245c770
< 5.0.19
MEDIUM 5.6 The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions … wordfence
8b4a47f7-0161-4a57-994f-c48795810ea3
< 1.7.5
MEDIUM 5.6 The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shor… wordfence
3faf976d-0763-4e47-9bc3-18c791ec4487 MEDIUM 5.6 The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.8.3. … wordfence
1d2da608-81a4-47b5-b23d-d18ab7bc2aa9
< 3.6.5.6
MEDIUM 5.6 The AI WP Writer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several … wordfence
11d45287-f875-4cc9-aaf6-47158fe32858
< 1.9.8
MEDIUM 5.6 The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… wordfence
ff656409-2344-4190-a731-5a282e21375c
< 2.7
MEDIUM 5.5 The Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to… wordfence
ff1f81e8-64ed-4330-9c76-1a8d2e2d307d
< 2.11.23
MEDIUM 5.5 The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order_mail' setting in… wordfence
← Prev 1018 1019 1020 1021 1022 1023 1024 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top