🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1077 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
805e3eba-639e-48a1-a867-a2c56fa01081
< 1.1
MEDIUM 5.4 The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-… wordfence
804dafd1-0f18-4248-a243-8b26d161bc85
< 1.2.2
MEDIUM 5.4 Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Googl… wordfence
8030c334-458a-4d21-9a64-3f5df715ba97
< 4.3.3
MEDIUM 5.4 The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including… wordfence
801d6f21-1f52-48d4-9f8e-5c971dd037f7
< 3.7.21
MEDIUM 5.4 In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API. wordfence
7fdb93fa-e9b4-4d00-8bb3-ff171a916b65
< 4.0.3
MEDIUM 5.4 The MainWP Page Speed Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and includ… wordfence
7fbbd0d7-882f-4bc8-a67a-4d6dc05cb796
< 1.8.2.2
MEDIUM 5.4 The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… wordfence
7fa5ac48-57b6-4367-81a0-8310360d0c7d
< 1.5.5
MEDIUM 5.4 The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers… wordfence
7f787c75-7b27-4256-ac0c-abc2988ea7c8
< 6.2.1.6
MEDIUM 5.4 The Auto Affiliate Links plugin for WordPress is vulnerable to improper access control via multiple AJAX actions in vers… wordfence
7f4c0bd6-f289-4a52-ac11-345076c32d84
< 2.5.4
MEDIUM 5.4 The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t… wordfence
7f17e055-ad49-4115-89c5-dd76b6c531f7
< 4.0.3
MEDIUM 5.4 The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unautho… wordfence
7f01ad95-7a51-408c-917f-4350dbeabb2b
< 3.8.0
MEDIUM 5.4 The Editorial Calendar plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and inc… wordfence
7ee188cc-2c3f-45e7-b7ce-928242035e37
< 2.9.1.7
MEDIUM 5.4 The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in a… wordfence
7edad4f6-e470-4a72-b618-d2dad64e0ac1
< 6.3.1
MEDIUM 5.4 The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in th… wordfence
7dfd0246-4265-4dde-8a1e-18b7042eae74
< 1.1.4
MEDIUM 5.4 The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to … wordfence
7dcd3452-a340-44e5-b292-347dc69ab863 MEDIUM 5.4 The Regina Lite theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versio… wordfence
7dc6d1db-37ae-4198-84bd-944dad4926c7
< 1.3.83
MEDIUM 5.4 The Appointment Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
7d500729-3b1a-4ece-81de-4c1f9afbf798
< 1.1.5
MEDIUM 5.4 The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
7d4ae4a7-aec1-4cc1-bea0-61dde44027fc
< 5.7.35
MEDIUM 5.4 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… wordfence
7d30e813-010f-4881-8b8e-f3d62d928c57
< 3.7.1
MEDIUM 5.4 The Easy Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block settin… wordfence
7d19800a-bff3-414f-a809-0159f49d263a
< 1.4.1
MEDIUM 5.4 The Custom Order Numbers for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
7cc96e83-28d9-4c6e-876f-23f1836ffd74
< 2.1.4
MEDIUM 5.4 The Google Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' URL parameter in versi… wordfence
7cbc157b-4f1b-4212-9e5c-dd10dd443df7
< 2.8.0
MEDIUM 5.4 The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plug… wordfence
7c9b9ab3-ecfa-49d0-820f-4edb5abae9ee MEDIUM 5.4 The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
7c89eb8e-bbd1-4c26-84ed-74456a6157a1 MEDIUM 5.4 The Oshine Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
7c6fe986-df68-4a62-9a43-5632c622b5fc
< 1.11.2
MEDIUM 5.4 The “Elementor Addon Elements” WordPress Plugin before 1.11.2 has several widgets that are vulnerable to stored Cros… wordfence
← Prev 1074 1075 1076 1077 1078 1079 1080 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top