πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1069 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
af73240c-b711-4e91-9998-5f7e6a9a4fb9
< 2.7.10
MEDIUM 5.4 The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.… wordfence
af695224-24e7-4d5b-b472-dee53eb6073f
< 1.3.9
MEDIUM 5.4 The Podlove Subscribe button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
af468138-c10a-4f9b-b714-0425d52f0210
< 4.16.5
MEDIUM 5.4 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
af3675c9-3a6b-4139-85e8-2fc57f290e82
< 4.3.0
MEDIUM 5.4 The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all … wordfence
af0579f3-09f8-46cc-9ba8-647a8ec83076
< 1.4.11
MEDIUM 5.4 The Stripe Payments For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
aefb192a-ed42-44a9-bbd1-5906909a419c
< 2025
MEDIUM 5.4 The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Requ… wordfence
ae8dbf54-ea62-4901-b34f-079b708ca0b5
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
ae7549db-9a4b-4dee-8023-d7863dc3b4c8
< 3.3.1
MEDIUM 5.4 The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_first_na… wordfence
ae6d07eb-3e64-45ee-ad5d-92b41ef11e43
< 4.11.71
MEDIUM 5.4 The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored… wordfence
ae6a00ef-1a3f-47cd-9e55-f28b74999198
< 4.1.1
MEDIUM 5.4 The Estatik Real Estate Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … wordfence
ae46eea5-4b7a-4cf5-97ff-c65b7e8e3261
< 4.0.1
MEDIUM 5.4 Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead t… wordfence
ae40fd4a-8448-48ea-9b31-067643972b44
< 10.4.37
MEDIUM 5.4 The Connections Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'connection… wordfence
adfc5084-ed33-4600-bd34-d3516f1a1b96
< 1.4.2
MEDIUM 5.4 The WordPress Backup & Migration plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… wordfence
adb84461-6675-497f-ac53-cf72bd4c17bc
< 2.0.6
MEDIUM 5.4 The WPFront Scroll Top WordPress plugin before 2.0.5 does not sanitise or escape its Image ALT setting before outputting… wordfence
ada3a69c-d113-4f92-b716-641bd5d20940
< 4.9.1
MEDIUM 5.4 Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress pl… wordfence
ad979f36-319f-48ce-a620-5ea9ae5401eb
< 1.4.0
MEDIUM 5.4 The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role a… wordfence
ad50e216-f522-4294-a4dc-7f3bd52820b3
< 2.1.1
MEDIUM 5.4 The Doofinder for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data and loss of data d… wordfence
ad359327-9d53-4c8e-bd09-7a337711cfbd
< 2.3.19
MEDIUM 5.4 The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, w… wordfence
acbe1c36-04e7-49af-90fa-d8acbe351b57
< 2.0.52
MEDIUM 5.4 The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade. wordfence
ac9a3848-f486-475b-b2c7-ea1007bb30d3
< 2.12
MEDIUM 5.4 The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capabil… wordfence
ac86043d-caf9-4c25-86b2-0e063c21b2d7
< 5.2.7
MEDIUM 5.4 Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email … wordfence
ac8214af-00d0-4dde-a3e7-f657decc4b93
< 2.7.27
MEDIUM 5.4 The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cr… wordfence
ac763936-7147-4100-8a46-4c6d2f2224b4 MEDIUM 5.4 The idbbee plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idbbee' shortcode in vers… wordfence
ac10b30d-1fe3-46f4-a4fc-fa2acd7f9db4
< 1.3.40
MEDIUM 5.4 The Falang multilanguage plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
abf4cfb9-745a-4b4f-8862-54ef561904d6
< 3.0.0
MEDIUM 5.4 The Mass Delete Unused Tags plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
← Prev 1066 1067 1068 1069 1070 1071 1072 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top