πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1056 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f5d42dc6-047f-45ff-9a7a-5a7738f7dcb5
< 2.2.6
MEDIUM 5.4 The Safe SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up t… wordfence
f5ba832e-98bc-421d-9b60-e6260c408815
< 1.0.274
MEDIUM 5.4 The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri-gal… wordfence
f5b00784-9120-403d-9788-3cd3c3c020aa
< 2.3.16
MEDIUM 5.4 The WP Dynamic Keywords Injector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
f55a9d35-596c-4207-be11-ade1127df369
< 7.3.7
MEDIUM 5.4 Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker … wordfence
f4f96877-406b-4ec0-ac6b-ee1ffdb436e5
< 3.1.8
MEDIUM 5.4 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
f4dfb4b5-b2a5-40bd-9dfb-863baa563d06
< 2.9.9.4.1
MEDIUM 5.4 The Pinpoint Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
f4b13a45-9141-47e3-ba11-c0ce15235936
< 1.2.57
MEDIUM 5.4 The WooCommerce Shipping – DPD baltic plugin for WordPress is vulnerable to authorization bypass due to a missing capa… wordfence
f4955368-85bc-4a9c-8d3a-446e09955f6c
< 4.0.2
MEDIUM 5.4 The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.… wordfence
f434585c-8533-4788-b0bc-5650390c29a8
< 4.5.2
MEDIUM 5.4 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request… wordfence
f42dc6ab-4035-4e9e-b956-40395c7e309f
< 1.8.8
MEDIUM 5.4 Cross-site request forgery (CSRF) vulnerability in the WP Maintenance Mode plugin before 1.8.8 for WordPress allows remo… wordfence
f419b83c-9253-4ca6-a02a-7daad1819581
< 3.3.2
MEDIUM 5.4 wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access… wordfence
f4083d48-a1a8-4ab7-a67f-308bbbbcb4d5
< 1.9.3
MEDIUM 5.4 The USPS Shipping for WooCommerce – Live Rates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
f3d5bc99-2b55-4e19-8304-e56f3d4a2f1a
< 6.12.4
MEDIUM 5.4 The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access of data and modification of … wordfence
f3d4283e-ea57-41e1-baeb-f8f70cad3020
< 2.6.4
MEDIUM 5.4 The myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin plugin for WordPress is vulnerable to Store… wordfence
f3d243fe-062c-4f46-aa85-cb7662a7615a
< 1.1.1
MEDIUM 5.4 The Ultimate Watermark plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
f3d08ac9-22f7-45f4-9896-05b90f5fce64
< 3.0.9
MEDIUM 5.4 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of us… wordfence
f3b79fab-208f-4354-89ea-508290dcd851
< 1.4.5
MEDIUM 5.4 The MailerLite – Signup forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
f3a5bb9c-0fc3-4a1b-8b4d-a700cbf9dacc
< 1.1.22
MEDIUM 5.4 Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers… wordfence
f397550a-08f6-47d5-8425-e715ad693d6e
< 1.3.9
MEDIUM 5.4 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to… wordfence
f38fc5ed-d4e7-46a8-9983-9bf28444db99
< 2.4.2
MEDIUM 5.4 The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with … wordfence
f330fa5a-b471-45ee-a2a6-3ae8f3941bfe
< 0.8.6
MEDIUM 5.4 The Contact Form 7 + Telegram plugin for WordPress is vulnerable to unauthorized modification of data and loss of data d… wordfence
f32c66b3-b26c-4fe3-9171-ca8780391a2a MEDIUM 5.4 wordfence
f321e41a-3945-47db-a215-aeb001b7b80b
< 2.0.87
MEDIUM 5.4 The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_str… wordfence
f2ff2cc6-b584-442b-890b-033a0a047c24
< 5.9.9
MEDIUM 5.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
f2a61a12-df0c-47a2-ba39-b70dbfaddf0a
< 1.5.4
MEDIUM 5.4 The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does… wordfence
← Prev 1053 1054 1055 1056 1057 1058 1059 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top