πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1076 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
858d8641-7455-47c2-9639-480ce4ec3540
< 1.9.2
MEDIUM 5.4 The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode e… wordfence
84cd2529-7b9b-47c2-9e9c-72bb208a60e6 MEDIUM 5.4 The WP Triggers Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
84b616fa-ff64-49e8-8c4a-7d7bfdf758be
< 2.5.7
MEDIUM 5.4 The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up … wordfence
84846d95-792d-4569-b0eb-876d82d0beee
< 5.0.05
MEDIUM 5.4 The AIKTP plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on… wordfence
840ba5b2-838a-455a-b39d-865f89c05249
< 9.0.47
MEDIUM 5.4 The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all … wordfence
83dfd6a2-2944-42a9-9e3d-60836ebfb106
< 6.7.5
MEDIUM 5.4 The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
83d63545-00f3-411b-9d4a-6837759bc3af MEDIUM 5.4 The Better Author Bio plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
83cb1333-3c74-426d-9838-a5cb90be29b2
< 2.1.0
MEDIUM 5.4 The wpForo Forum plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 2.0.9. This is d… wordfence
8390ab61-197a-4eb7-a589-47bf46a0e123
< 2.46.1
MEDIUM 5.4 The Simple Giveaways plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
834c4ca9-7173-4c84-8287-9916ec72935d
< 2.6.2
MEDIUM 5.4 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data d… wordfence
830663b6-0786-48c7-9ffd-ac3ba2bd3e0c
< 3.6.8
MEDIUM 5.4 The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up t… wordfence
82cee07d-871a-4579-aa53-ca0d14315458
< 13.3
MEDIUM 5.4 The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited fi… wordfence
82cde234-ae87-438f-911e-bdd0e3ac1132
< 5.6.4
MEDIUM 5.4 The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Ob… wordfence
824ec2ba-b701-46e9-b237-53cd7d0e46da
< 3.14.2
MEDIUM 5.4 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and de… wordfence
824b27e8-1f07-4cd0-9335-5860d1b58562 MEDIUM 5.4 The bookmarkify plugin 1.1.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify… wordfence
822a3b3b-db39-4edc-ae68-80fb82359316
< 1.6.8
MEDIUM 5.4 The WordPress RSS Feed Retriever plugin for WordPress is vulnerable to authorization bypass due to a missing capability … wordfence
819e2a4a-d282-4c52-852a-e3a2051a04e9
< 2.0.10
MEDIUM 5.4 The Klarna Checkout for WooCommerce plugin for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and … wordfence
8198d81a-40c0-49c1-8c38-f5ef6fb911ad
< 4.9.4
MEDIUM 5.4 The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to authorization bypass in all ver… wordfence
818d3418-8e14-49b9-a112-8eab9eb3c283
< 4.8.1
MEDIUM 5.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Link in al… wordfence
8175ff00-e588-46cf-a743-9c4d4717657a MEDIUM 5.4 The Amazon affiliate lite Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
816bcd51-2424-41a1-8a0d-583268d8c6cd
< 3.6.6
MEDIUM 5.4 The The Textmetrics plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inclu… wordfence
8149103e-105d-401d-8a15-b07d131baaac
< 1.32.1
MEDIUM 5.4 The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
80bb4009-7857-4af4-9c55-0ef69b538e6f
< 2.2.5
MEDIUM 5.4 The BuddyPress Docs plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and in… wordfence
80ae05c4-64de-48df-b302-6110403b79d0
< 1.7.3
MEDIUM 5.4 The Easy PayPal Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting … wordfence
80797183-c69f-4dce-a2e0-52a395ceffaa
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
← Prev 1073 1074 1075 1076 1077 1078 1079 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top