πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1080 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7449ed1e-cc09-4b8b-8226-7cdc70be2b36
< 4.2.6.9
MEDIUM 5.4 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ve… wordfence
7414779e-7241-4ab2-9b1f-34c3e1acc66b
< 2.0.0
MEDIUM 5.4 The Doofinder for WooCommerce plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.5.… wordfence
73b93a44-1d91-4755-ae48-73f74a6fe415
< 3.2.3
MEDIUM 5.4 The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the a… wordfence
738a9651-974e-4861-be7a-2d9b191d582b
< 5.9
MEDIUM 5.4 Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers t… wordfence
736d08ca-3f65-4232-96a9-303bafbf3471
< 4.0.0
MEDIUM 5.4 The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
731cbeed-d4aa-448f-878a-8c51a3da4e18
< 4.3.0
MEDIUM 5.4 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modif… wordfence
72fa6b56-dfbf-4c27-a6f3-418d1ab5dc0f
< 2.0.5
MEDIUM 5.4 lara-google-analytics.php in Lara Google Analytics plugin through 2.0.4 for WordPress allows authenticated stored XSS. wordfence
72dc919a-c13d-49b4-927d-a0bb837b63dd
< 17.9
MEDIUM 5.4 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to … wordfence
72bcfd2a-6803-4073-8fa9-62bcf0a10571
< 2.5.8
MEDIUM 5.4 The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all vers… wordfence
72934d2f-fd52-46d1-8cf9-9a20968899f7
< 5.3.15
MEDIUM 5.4 The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability c… wordfence
71f58781-3fb3-4eba-8e5a-f98f006f4607
< 4.4.3
MEDIUM 5.4 The WP Google Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
71d916aa-5382-495b-8142-80de0a0912e7
< 1.1.6
MEDIUM 5.4 Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lea… wordfence
71b3bec2-3fb2-4b0a-aa6d-5c761d0796e2
< 1.13.5
MEDIUM 5.4 The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a… wordfence
711d2c4d-700d-4d6e-911f-99abf86eff32
< 3.0.4
MEDIUM 5.4 The CBX Currency Converter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
71114965-c8e3-4f2f-b308-f75adc7f2d31
< 0.9.4.1
MEDIUM 5.4 Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is e… wordfence
70cd028d-122d-4e3c-ac09-150dec07a2cd
< 2.4.3.2
MEDIUM 5.4 The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
70434876-4876-4da8-9af1-6f6ef5632f26
< 1.1.20
MEDIUM 5.4 The Same Category Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget title placehold… wordfence
7036400d-022c-4e7e-a463-6ac6f5373474 MEDIUM 5.4 Multiple cross-site scripting (XSS) vulnerabilities in the esb-csv-import-export plugin through 1.1 for WordPress allow … wordfence
702f9d3b-5d33-4215-ac76-9aae3162d775
< 4.5.4
MEDIUM 5.4 The WP Meta SEO plugin for WordPress is vulnerable to unauthorized options update due to a missing capability check on t… wordfence
6fd4fa08-e326-47ab-96b1-be7b702a32ff MEDIUM 5.4 Cross-Site Request Forgery (CSRF) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPr… wordfence
6fb9c8c3-e491-4bca-adeb-b87d9f8f3b32
< 1.3.9
MEDIUM 5.4 The Legal Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.8… wordfence
6f6ece0e-7c7c-4c9b-b860-3b279e98c087
< 2.8.3
MEDIUM 5.4 The Recipe Card Blocks by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
6f17d54b-4890-455b-832f-9fa2376ab819
< 6.7
MEDIUM 5.4 The Hercules Core plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
6f14f19d-95b3-474b-a2ea-d846c85644cd MEDIUM 5.4 The Maintenance Switch plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
6f01ecab-2dfe-45d2-9d9a-ba1e30c7d75f
< 4.7.4
MEDIUM 5.4 The Molongui plugin for WordPress is vulnerable to unauthorized modification and access of data due to missing capabilit… wordfence
← Prev 1077 1078 1079 1080 1081 1082 1083 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top