🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1057 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f28e36e9-7d02-48fc-8f20-64a951af75e0 MEDIUM 5.4 Hermit 音乐播放器 <= 3.1.6 is vulnerable to Cross-Site Request Forgery. This allow attackers to delete cache, delet… wordfence
f28afb93-b72a-4a56-994b-144124202147
< 1.13.5
MEDIUM 5.4 The Custom Post Type UI for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.13… wordfence
f288b68a-2455-4ee7-b217-5cb46fb79caf MEDIUM 5.4 The JW-Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions u… wordfence
f26fcef3-6d94-46f6-9832-bdb03b6cb867
< 1.3.02
MEDIUM 5.4 The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/a… wordfence
f2448450-9d0e-42bc-bfdb-66861b2f212c
< 1.9.7
MEDIUM 5.4 The Gravityforms plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.6 due … wordfence
f21100f4-f655-41e6-a31c-70ce4dfb1ba6 MEDIUM 5.4 The Ceceppa Multilingua plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' GET parameter… wordfence
f1d72e60-182f-4210-a190-e0a7f0237ed1
< 1.9.31
MEDIUM 5.4 The Text To Speech TTS Accessibility plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… wordfence
f15af4eb-5752-4a85-babd-cee7e89c329d
< 2.0.0
MEDIUM 5.4 The Auto Prune Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
f0b95670-0767-4325-88d0-4ae6d7302558
< 1.3.1
MEDIUM 5.4 The Funnel Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… wordfence
f0859e21-851a-4a6d-aa6c-9f759c5866d9
< 8.9.1
MEDIUM 5.4 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Missing Authorization in all v… wordfence
f06d1b9e-e27d-4c43-a69b-7641518e4615
< 1.3.33
MEDIUM 5.4 The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'tw… wordfence
f040d5b9-0db2-467b-91fa-98aede9f7280 MEDIUM 5.4 The Subscribe to Category plugin for WordPress is vulnerable to authorization bypass due to a missing capability check o… wordfence
efe846aa-6de2-40f0-81c6-f7ca98a55f23 MEDIUM 5.4 The Popup Surveys & Polls for WordPress (Mare.io) plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
ef5859b7-0f15-43ad-9f45-aa846d045f5d
< 2.4.14
MEDIUM 5.4 The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
ef2f1ad1-1e2e-4b56-b16c-d87956b142ad MEDIUM 5.4 The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all vers… wordfence
ef0dc868-f617-408f-9333-ebfee4897701
< 1.9
MEDIUM 5.4 The BruteBank plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8. Th… wordfence
eeac5489-7eba-43b6-b7fb-1ce062285948 MEDIUM 5.4 The Fence URL wp-login.php plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
ee78642c-ad2a-4012-94e8-e01f71863791
< 2.0.6
MEDIUM 5.4 The wpForo Forum plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… wordfence
ee74d229-499e-4f9a-ad7d-c707f6eeac6e
< 2.9.22
MEDIUM 5.4 The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
ee52c6c0-c69e-46c4-9e4b-94aa69c00737
< 1.11.8
MEDIUM 5.4 The Easy Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
ee520664-0c1f-4af0-8cdf-a33c1dfaaca7
< 1.2.0
MEDIUM 5.4 The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to missing authorization due to a missing … wordfence
ee1ee4c4-871d-4a3d-8ca6-3675d248d5e8
< 8.2.6
MEDIUM 5.4 The Soledad plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on one of its f… wordfence
edf5ba29-2fc5-4839-abde-999f6b686749 MEDIUM 5.4 The Attendance Manager plugin for WordPress is vulnerable to SQL Injection via the 'attmgr_off' parameter in all version… wordfence
edcf46b6-368e-49c0-b2c3-99bf6e2d358f
< 4.1.38
MEDIUM 5.4 WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ paramet… wordfence
ed79e382-acb4-4348-9bc6-b44ec0d75fb5
< 1.9.1
MEDIUM 5.4 The Depicter Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on multi… wordfence
← Prev 1054 1055 1056 1057 1058 1059 1060 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top