πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1070 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
aba88c4c-93a4-4c1c-b239-68b5fec87146
< 1.4.13
MEDIUM 5.4 The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modi… wordfence
aba54af1-732a-49e6-a8c4-76f276a5581a
< 2.7.27
MEDIUM 5.4 The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cr… wordfence
ab922406-4af8-4ef2-bcc8-c326212546b1
< 1.1.3
MEDIUM 5.4 The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Server-Side Request Forgery i… wordfence
ab633506-63a1-4be1-b402-c7f0bcc4ea7a
< 1.1.4
MEDIUM 5.4 The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du… wordfence
ab346cea-2d33-4ec5-b985-86a65fbe12e2
< 4.0.4
MEDIUM 5.4 The MainWP Rocket Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and including … wordfence
aac9e0cb-cc1e-4041-bb92-21f94c8d35fd MEDIUM 5.4 The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise,… wordfence
aa769d51-8718-42e9-9070-0b878442dbc7 MEDIUM 5.4 The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on… wordfence
aa6adda7-5eba-483c-a759-6f8a92da75e3
< 4.0.3
MEDIUM 5.4 The MainWP iThemes Security Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and … wordfence
a9ee90c4-e9ab-426e-8b92-217de43bd2e4
< 2.6.4
MEDIUM 5.4 The Workreap theme for WordPress is vulnerable to insecure direct object reference in versions up to, and including, 2.6… wordfence
a9b074ed-2edd-4774-b0b2-dc08c9647094
< 2.7.8
MEDIUM 5.4 The Popular Brand Icons – Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortco… wordfence
a9af1429-32c5-4907-acf4-83efc6727bb8
< 2.25.2
MEDIUM 5.4 The GiveWP plugin for WordPress is vulnerable to Improper Authorization in versions up to, and including, 2.25.1. This m… wordfence
a99a64f7-1ea8-4de6-b24f-1f69bf25c1f5
< 3.24.0
MEDIUM 5.4 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
a9939ffe-a5d5-45cb-b673-665acf1ff09d
< 2.25.2
MEDIUM 5.4 The GiveWP plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.1. This is due to m… wordfence
a94accad-27c7-462b-b26f-0dde2036a7ba MEDIUM 5.4 The Spider Facebook plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
a92beff1-3bc6-459e-aeca-5cbdf2152388
< 4.4
MEDIUM 5.4 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a… wordfence
a886bec4-acd6-4a15-aa42-7c31270ae1e0 MEDIUM 5.4 The Table Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, … wordfence
a8394cec-7921-40a7-816e-b3875d4adb6d MEDIUM 5.4 The Post Carousel Slider for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
a8292a1f-1d26-4efa-9ead-5309965bdb8c
< 0.9.9
MEDIUM 5.4 Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPres… wordfence
a7d0deb3-3d04-4f85-b769-0894d7c6ee7c
< 6.6.3
MEDIUM 5.4 The Easy Forms for Mailchimp plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including… wordfence
a7ce9573-eda5-45c0-8775-966f2fbe9496
< 2.5.0
MEDIUM 5.4 The Participants Database plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
a75020c0-8286-449a-9c51-0b1488350f09 MEDIUM 5.4 Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress… wordfence
a72ce900-7999-45ee-a46a-6dd0a8f5931d
< 8.2.0
MEDIUM 5.4 The WP Live Chat Support for WordPress is vulnerable to Stored Cross-Site Scripting via the quick response and post func… wordfence
a6dadbb0-1ebe-43ff-b220-0c93d0f51d87 MEDIUM 5.4 The Custom Order Statuses for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
a6689ddc-91df-44d4-aff2-9453978c5ff6
< 1.4
MEDIUM 5.4 The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.… wordfence
a649fbea-65cf-45c9-b853-2733f27518af
< 1.0.14
MEDIUM 5.4 The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulne… wordfence
← Prev 1067 1068 1069 1070 1071 1072 1073 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top