πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 103 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ffaf7a75-de27-4361-ba04-ff17151b7eb5 CRITICAL 9.6 The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its setti… — wordfence
fc9dfe96-2d43-4b7b-a91a-87cdaaab8e49
< 1.7.2
CRITICAL 9.6 The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX act… — wordfence
f908837d-2bba-45db-b005-f685a33cd71e CRITICAL 9.6 The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could a… — wordfence
f8bcf51a-36ee-4d4d-b9d6-d9db0dafd791
< 2.32.11
CRITICAL 9.6 The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arb… — wordfence
f4703ca7-0677-4128-b9b7-31132ff1804d
< 4.2
CRITICAL 9.6 The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to CSV Injection in versions up … — wordfence
ef5028a0-6a5a-40ad-92df-ffc988cad389
< 4.09.05
CRITICAL 9.6 The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img… — wordfence
d8e23501-9fc4-484b-b308-a9c51494bc9d CRITICAL 9.6 The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could … — wordfence
cacd31bd-ccc6-49fa-89f1-09f3c5cd9072
< 4.4.5
CRITICAL 9.6 The Captcha plugin for WordPress contained a backdoor that injected SEO spam into unsuspecting users WordPress sites in … — wordfence
c8abcc7b-6c68-4fc8-81af-e88624e417dd
< 5.1.0
CRITICAL 9.6 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… — wordfence
c79a173d-b9c3-4554-95e7-2a4b87382079 CRITICAL 9.6 The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, whic… — wordfence
b5490dd9-20d5-4cd6-bc09-5da94d3e702f
< 4.1.5.3
CRITICAL 9.6 The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discov… — wordfence
a50531df-e876-463c-a06b-16b2f30aeefe
< 3.7.29
CRITICAL 9.6 WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated use… — wordfence
9e6365ab-30c5-4bec-a5f3-b0812ae8a609
< 2.4.1
CRITICAL 9.6 The New User Approve WordPress plugin before 2.4.1 does not have CSRF check in place when updating its settings and addi… — wordfence
9e3f199b-b75d-43a2-a20c-957fb1b512e1 CRITICAL 9.6 The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache image… — wordfence
92d59dd4-7338-40ac-9a73-37e9e85351d7
< 3.1.1
CRITICAL 9.6 Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.1.0 and earlier allow remote attacker… — wordfence
8f4ae82c-f249-4094-a0ef-568c3a30d16b CRITICAL 9.6 The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, wh… — wordfence
8df77bb7-4453-403d-8d35-66251f6d399c CRITICAL 9.6 The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allo… — wordfence
8b776a8a-b071-4caf-9e67-6f08ace4da2a
< 2.5
CRITICAL 9.6 The ND Booking plugin for WordPress is vulnerable to arbitrary options update in versions up to, and including 2.4, due … — wordfence
82acefe0-a839-4721-858d-120326e45664
< 3.1.4
CRITICAL 9.6 The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make… — wordfence
812d99bc-8d86-44a9-bafa-be8ce979229c
< 3.7.10
CRITICAL 9.6 Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers t… — wordfence
7ffac29d-d1cc-4d5d-aff8-0cb639a1e3d7
< 2.8.5
CRITICAL 9.6 EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving … — wordfence
7ea13a80-c744-4de3-ac19-178b67e1afc4 CRITICAL 9.6 The MyAnime Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… — wordfence
7817a840-325a-4709-8374-84bb32d98d0e
< 1.25.0
CRITICAL 9.6 The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.… — wordfence
6eb3ad80-3510-4018-91af-b733ef62e28f
< 2.1
CRITICAL 9.6 The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… — wordfence
65b2b72a-5c76-463e-9513-26b400b40a65 CRITICAL 9.6 The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its setting… — wordfence
← Prev 100 101 102 103 104 105 106 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top