πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1071 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a5deac61-031f-452a-a478-d5d0c7953817
< 1.3.1
MEDIUM 5.4 The Stop Referrer Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
a438ec56-8ddc-4cea-8d93-c8f79b46f47e
< 4.5.4
MEDIUM 5.4 The Publish to Schedule plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
a3f7e1a4-88b2-4069-adb8-d51278b48234
< 3.7.2
MEDIUM 5.4 The WooCommerce Enhanced Ecommerce Analytics Integration with Conversion Tracking plugin for WordPress is vulnerable to … wordfence
a39679a6-21f1-41e2-aaf8-23f03b79ef33
< 1.6.5
MEDIUM 5.4 The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is vulnerable to unauthoriz… wordfence
a36d1bb1-9446-4042-a1ec-08a3ffdcb744
< 4.4.0
MEDIUM 5.4 The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.… wordfence
a32f50f7-d271-45f6-9a73-838a8dcb901f
< 7.3.6
MEDIUM 5.4 The Themify Ultra theme for WordPress is vulnerable to unauthorized use of functionality due to a missing capability che… wordfence
a32dcf96-ec75-46b1-8f1d-608411ad5147
< 2.8.5
MEDIUM 5.4 The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' para… wordfence
a3233f6f-7488-43ed-a626-b2150c5516fc
< 3.1.32
MEDIUM 5.4 The Ditty plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.31… wordfence
a2b809f5-0384-43f5-8839-67bf059360eb MEDIUM 5.4 The Donation Button plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the … wordfence
a29b18d4-7b9b-48c9-aea8-88f6a6fc4b29 MEDIUM 5.4 XSS exists in the amtyThumb amty-thumb-recent-post (aka amtyThumb posts or wp-thumb-post) plugin 8.1.3 for WordPress via… wordfence
a25a00b5-baf3-4175-b242-857c1f79b9a2 MEDIUM 5.4 The Misiek Photo Album plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
a1ab02c0-e083-4f0e-b6d4-1a10ade2c688
< 3.30
MEDIUM 5.4 The Leyka plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.29.2. Thi… wordfence
a19ef0d7-fd44-45ea-8fb1-b99c270072c4
< 3.0.2
MEDIUM 5.4 wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Sup… wordfence
a1702bdd-1409-42f7-b7b8-cfd44505ecd6
< 4.2.7.2
MEDIUM 5.4 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Open Redirect in all versions up to, and i… wordfence
a156234f-2644-4d17-aaa5-4f088cf48f73
< 6.4.4
MEDIUM 5.4 The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post… wordfence
a0ea0d46-a6aa-4704-8e4e-051bedd4994e
< 7.6.1.0
MEDIUM 5.4 Cross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin before 7.6.1.0 for WordPress allows remo… wordfence
a0707c92-96e9-444a-8a13-52d49c9e3f5c
< 3.2.1.1
MEDIUM 5.4 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the P… wordfence
9fe7f4e4-3774-408b-8a2a-0db67bc34fcf MEDIUM 5.4 The Pocket News Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
9fdc9d20-a1cf-4a58-b250-4f3f56b77b69
< 4.3.0
MEDIUM 5.4 The WP OAuth Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… wordfence
9fc1e720-46ba-4f57-8694-551936371e2c
< 1.7.6
MEDIUM 5.4 The Browser Screenshots WordPress plugin before 1.7.6 allowed authenticated users with a role as low as Contributor to p… wordfence
9f6b9a90-4fa8-4cd0-bec8-6fa69a1b4681
< 3.5.2
MEDIUM 5.4 The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified… wordfence
9efbbb82-8127-4f11-84d4-2ce27f2cbefe MEDIUM 5.4 The Word Search Puzzles game plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
9ea7ccb0-c0fb-4ef3-8041-9bf5abe36e3f
< 2.0.9
MEDIUM 5.4 The MailerLite – WooCommerce integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
9e60428e-1641-470f-a6f1-7c2b4140a6bf
< 6.1.8
MEDIUM 5.4 Cross-Site Request Forgery (CSRF) in Use Any Font (WordPress plugin) <= 6.1.7 allows an attacker to deactivate the API k… wordfence
9e1f94d9-8be6-4174-90a5-820c0207a2fa
< 25.2.1
MEDIUM 5.4 The Clever Fox – One Click Website Importer by Nayra Themes plugin for WordPress is vulnerable to unauthorized modific… wordfence
← Prev 1068 1069 1070 1071 1072 1073 1074 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top