πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1073 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
96e12fa5-eba4-4f69-ae3a-7e460bfa9e5d
< 7.5.2
MEDIUM 5.4 The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upl… wordfence
968d5d31-2592-4bed-9d18-5877f0d6062e
< 3.3.1
MEDIUM 5.4 The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing… wordfence
966a3a33-3d22-4671-8893-7a64ff838f39
< 1.3.2.5
MEDIUM 5.4 The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.… wordfence
963c2d10-692b-4447-8d0b-7ccc2e533f01
< 4.5.2
MEDIUM 5.4 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modif… wordfence
95d2a05d-67ae-45b1-8add-0dcf73d43181
< 5.9.4.3
MEDIUM 5.4 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Requ… wordfence
958118ec-437e-45c8-a0f0-6aaf54e60d04
< 2.19.14
MEDIUM 5.4 The RabbitLoader plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missi… wordfence
954ef157-ecd1-42bd-b288-d5866b9c11f0 MEDIUM 5.4 The Shortcut Macros WordPress plugin through 1.3 does not have authorisation and CSRF checks in place when updating its … wordfence
954b8064-f317-4af4-a55f-9a61ee945006
< 3.7.38
MEDIUM 5.4 WordPress Core in various versions < 5.9.2 and Gutenberg versions less than 12.7.2 are vulnerable to prototype pollution… wordfence
94efdb07-653b-4838-b584-e45e9ab9b7a5
< 5.10.2
MEDIUM 5.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
94ed918c-8f6f-4e1f-ab1d-e16632831951
< 3.7.2
MEDIUM 5.4 The ShortPixel Adaptive Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
94e0f4cd-55fa-42f4-8d56-c8598ade4dc7 MEDIUM 5.4 The Page and Post Lister plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
94df820c-cafb-4a43-ace1-ec396b1ae6c5
< 3.2.1
MEDIUM 5.4 The Cache Images plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the cac… wordfence
94d60fcb-a542-41a9-b6ac-6ac2607068aa
< 3.1.43
MEDIUM 5.4 The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to improper capa… wordfence
94abb34a-4451-4f41-ba23-d2a723e5a2e7
< 4.1.2
MEDIUM 5.4 The ShopEngine plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.1.… wordfence
946ba166-3309-4e47-8b6b-d3f017bbfcc8
< 2.2.11
MEDIUM 5.4 The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.2.10 due to in… wordfence
93875f19-d9b9-4e33-bba9-afc75cf26bf2
< 8.4.8
MEDIUM 5.4 The Salon Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
92e37b28-1a17-417a-b40f-cb4bbe6ec759
< 2.2.27
MEDIUM 5.4 The PDF Flipbook, 3D Flipbook – DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline… wordfence
92a543e2-1af1-4857-8e2f-c8658eac7fe0 MEDIUM 5.4 The Vrm 360 3D Model Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
9234b1ce-032f-487d-b60a-f80c78373238
< 3.21.1
MEDIUM 5.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up… wordfence
921d6de9-8c76-40f3-a6ed-eb749f5c446d MEDIUM 5.4 The Wp Svg Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions… wordfence
92058a88-7a65-4319-9f12-e38267e36c5c
< 30.1
MEDIUM 5.4 The WooCommerce Customers Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
918c418a-9d86-461d-91cb-33d04010c577
< 4.6.8
MEDIUM 5.4 The AI Infographic Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and in… wordfence
9163861b-735b-4007-97f7-8f9095d93ec9 MEDIUM 5.4 The IP Metaboxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via metabox settings in versions up t… wordfence
9116d719-f536-4b8a-9e73-9a8a922f8a35
< 4.0.3
MEDIUM 5.4 The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … wordfence
910d98a3-bfdb-4bb9-bd24-c57fa1a1a107
< 3.16.12
MEDIUM 5.4 Ultimate Addons for WPBakery up to 3.16.11 was affected by a Cross-Site Scripting vulnerability exploitable by lower lev… wordfence
← Prev 1070 1071 1072 1073 1074 1075 1076 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top