πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1058 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ed5cf097-1b27-4d20-b7b2-2aa909bce042
< 5.1.1
MEDIUM 5.4 The BuddyPress plugin for WordPress is vulnerable to Denial of Service in versions up to, and including, 5.1.0. This mak… wordfence
ed128ef2-0399-4daa-95f6-f5ba74281d89
< 2.2.3
MEDIUM 5.4 The Plugin for Google Reviews for WordPress is vulnerable to authorization bypass due to a missing capability check on t… wordfence
ed0a9db6-24bd-48ba-befa-ce537304ab52 MEDIUM 5.4 The Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder plugin for WordPress is vulnerab… wordfence
eca703ec-645c-4d12-ae57-75db14e08f3e
< 4.2.1
MEDIUM 5.4 The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to unauthorized modification of data due to improp… wordfence
ebfb4e11-e45c-437c-8b6e-887d0017dfbc
< 3.5.3
MEDIUM 5.4 The Gutentor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
eb9a6c9b-24fb-436f-b583-55adeedb726e
< 1.3.9
MEDIUM 5.4 The Podlove Subscribe button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
eb53282a-2298-4582-92bf-59221089172e
< 4.1.13
MEDIUM 5.4 The WP User Frontend plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
eb0b9c2b-c536-4697-be4c-7557ba66c2c4
< 4.5.11
MEDIUM 5.4 The WPML plugin for WordPress contains several AJAX actions that fail to perform capability checks or nonce checks. Thes… wordfence
eb088999-0727-4645-890b-f584b85cda48
< 7.1
MEDIUM 5.4 In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint … wordfence
eaeadd4b-a6f5-45fd-9324-77cf2e3bb978 MEDIUM 5.4 The PilotPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
eae9b960-36b1-4b83-855a-d1beaa60a93f
< 2.6.9.2
MEDIUM 5.4 The Exclusive Addons Elementor plugin for WordPress is vulnerable to unauthorized access of datadue to an insufficient c… wordfence
eab1fe39-dda2-49c9-9c76-c1127626a85c
< 4.6.2
MEDIUM 5.4 The WP-FB-AutoConnect plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
ea5215b3-fd25-4ca5-b651-18c935aa2ca0
< 1.2.0
MEDIUM 5.4 The AF Companion plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.1.0 to 1.1.2. This is du… wordfence
ea3c5188-4570-4958-8b2d-69048b10c5f9
< 6.3.10
MEDIUM 5.4 The Business Directory Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabilit… wordfence
e9c04973-cfb2-4b67-88e4-d527bb74df12 MEDIUM 5.4 The Private Content plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on sever… wordfence
e91e864a-20f6-48a2-ab9f-d20836207383
< 4.2.3.1
MEDIUM 5.4 The LearnPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on one of its… wordfence
e8b03deb-4134-4dde-8545-a14977a47209 MEDIUM 5.4 The WordPress Social Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter… wordfence
e7c18fbc-e212-4441-87ac-1e80ced0a128 MEDIUM 5.4 The DethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
e7b7e0b5-56a2-4f1f-be13-92721f4055fb
< 11.0.7
MEDIUM 5.4 The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorization and CSRF check in some o… wordfence
e7ad57d0-375b-4a64-a61c-90b72052552f
< 2.0.14.5
MEDIUM 5.4 The ListingPro theme before v2.0.14.5 for WordPress has Persistent XSS via the Best Day/Night field on the new listing s… wordfence
e7782522-78bc-4ad2-997e-81c8870d55fa
< 7.5
MEDIUM 5.4 The Comments – wpDiscuz plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and … wordfence
e7521577-ce13-4b60-ae11-9c0f9c077cf9
< 6.2.2
MEDIUM 5.4 The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in ve… wordfence
e7346f1e-a101-4131-8950-dbb0af4505f2
< 6.0.3.0
MEDIUM 5.4 The Community by PeepSo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
e72e87ae-f5c0-4582-a644-b90e93d98e74
< 3.7.13
MEDIUM 5.4 Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 … wordfence
e67ae204-2848-4389-a78d-7b3798e4ee54
< 1.19.3
MEDIUM 5.4 The Mail Mint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1… wordfence
← Prev 1055 1056 1057 1058 1059 1060 1061 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top