🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1055 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fd23b9cd-3492-4f6f-b90d-5215e175c1e3
< 3.7.26
MEDIUM 5.4 Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS. wordfence
fd12ce4a-585d-4e26-88fb-1ab9dcc8727d
< 2.8.3.1
MEDIUM 5.4 The RestroPress plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 2.8.3. Thi… wordfence
fcfb3a6e-7b58-4568-8439-e9c68a2223b9
< 5.1.9.3
MEDIUM 5.4 The RegistrationMagic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
fcb1f4db-3dba-4031-8196-66eec3203752 MEDIUM 5.4 The Facilita Form Tracker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
fc7bab78-4ebb-4be9-8891-1ac0e3ed0af3
< 1.2.0
MEDIUM 5.4 The Comment Blacklist Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
fc58c679-3e87-4bcc-b1bc-718ae52c291a
< 1.4.44
MEDIUM 5.4 The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution… wordfence
fc215aad-6988-434d-a623-be0b7f87189b
< 1.4
MEDIUM 5.4 The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.… wordfence
fafdd087-9637-41df-bc5a-97e1a02ea744
< 5.9.9
MEDIUM 5.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
fa52034e-3d11-4be5-ab8b-8f7256be2a3e
< 2.5.1
MEDIUM 5.4 The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions… wordfence
f9844b47-427a-4f2f-9f42-00adcbcf133c MEDIUM 5.4 The WCP Contact Form plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing… wordfence
f932e3ea-3d82-47af-924a-b2df15641611
< 4.0.4
MEDIUM 5.4 The MainWP Staging Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and including… wordfence
f9150e6b-2233-4fdb-95b7-1a5a8c083cad
< 4.0.3
MEDIUM 5.4 The MainWP WordPress SEO Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and inc… wordfence
f884ea43-e1a5-4b44-8a24-f68f71b0fcfb
< 2.9.2
MEDIUM 5.4 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ paramet… wordfence
f882da12-2db7-481f-9a16-a54e1ab24af5
< 2.4.9
MEDIUM 5.4 The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing … wordfence
f8575c46-e51d-4be9-85bf-024688c4607d
< 1.6
MEDIUM 5.4 The Advanced WordPress Reset plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘DBR_new_URI… wordfence
f7ae863c-4638-49ab-bb1f-52346884c3aa
< 1.2.5
MEDIUM 5.4 The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4… wordfence
f71453d9-8bbf-4546-b69f-e86cc41da9bd
< 1.1.3
MEDIUM 5.4 The Smart App Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
f70221e6-59a4-4151-9688-f06e194f51ac
< 2.13.0
MEDIUM 5.4 The Sheets To WP Table Live Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
f6e2ab69-2714-4bf9-a9ad-035fc15450f2
< 20220216
MEDIUM 5.4 The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
f6a41a90-d116-4cb5-9627-08eb70f9654d
< 2.5.9
MEDIUM 5.4 The SVG Support plugin for WordPress is running a vulnerable dependency (svg-sanitize, 0.14.1) in all versions up to, an… wordfence
f67ab0cf-340d-4234-a857-1883f91c3ab6
< 1.1.39
MEDIUM 5.4 The Popup Builder (Easy Notify Lite) plugin for WordPress is vulnerable to unauthorized modification of data due to a mi… wordfence
f62063c8-7559-492a-9caf-fae256052d1a
< 2.8.35
MEDIUM 5.4 The 10Web Booster plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the tw… wordfence
f618a350-e089-40f7-b731-7ffb9ece30b3 MEDIUM 5.4 The Contact Form With Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
f603a25f-7d56-4cf4-89aa-de87ee49522a
< 4.9
MEDIUM 5.4 The Delete Duplicate Posts plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capabili… wordfence
f5f59b16-b38a-451b-b220-044598872735
< 1.7
MEDIUM 5.4 The Meta Slider and Carousel with Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
← Prev 1052 1053 1054 1055 1056 1057 1058 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top