🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1081 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6ec069ef-7b53-47b5-93bc-92cfc2d62c88
< 1.3.4
MEDIUM 5.4 The ArCa Payment Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
6e98fb74-46f2-4a6a-8012-e2824bd77070
< 1.2.8
MEDIUM 5.4 The TH Variation Swatches plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
6e736e75-5ad4-4773-b1f7-358dc74848f0
< 3.3.0
MEDIUM 5.4 The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a … wordfence
6e2128db-ca9f-4211-8bc5-01a2cc1cba64
< 12.6.1
MEDIUM 5.4 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to unauthorized access of data d… wordfence
6df7bd57-7d2f-4098-b2d0-ffb2e8ed5868
< 1.1.2
MEDIUM 5.4 The Enable SVG, WebP & ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
6d9fb74d-58fd-4881-970d-86944c8784c4 MEDIUM 5.4 The KN Fix Your Title WordPress plugin through 1.0.1 was vulnerable to Authenticated Stored XSS in the separator field. wordfence
6d923bbe-5976-43c5-a34d-d2758c83f607
< 5.8.8
MEDIUM 5.4 The ProfileGrid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_c… wordfence
6cd49c60-e845-4dbb-b6b1-bd59aa1bb3ba
< 2.7.0
MEDIUM 5.4 The Crayon Syntax Highlighter Plugin for WordPress is vulnerable to authorization bypass due to a missing capability che… wordfence
6ca2be3b-b447-4621-8923-382b8b5255b0 MEDIUM 5.4 The Continue Shopping From Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
6c57f27b-2441-4f16-ab4b-bfb68b7b793f
< 3.5.0.9
MEDIUM 5.4 The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it … wordfence
6c4ae561-85f6-4fc5-bbd6-a4946dc1a714
< 6.5.1
MEDIUM 5.4 The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 6.5.1 (… wordfence
6c48f94b-d193-429a-9383-628ae12bfdf3
< 1.0.8.2
MEDIUM 5.4 The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to Cross-Site Reque… wordfence
6bcb9d95-acb4-4405-b785-1e5eace10dc9
< 4.10.1
MEDIUM 5.4 The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to unauthorized modificatio… wordfence
6badba6d-1ff1-4d6f-bccf-1f0278edb17d MEDIUM 5.4 The Random Text plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.3.0 due to insu… wordfence
6b87f741-4115-4ded-8dff-dc36cfdf1df1 MEDIUM 5.4 The Hyphenator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.5.… wordfence
6b226067-0287-4f7e-9415-dc3c83f2fd27
< 4.5.10
MEDIUM 5.4 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Store… wordfence
6a8d121d-434d-4445-874f-d3cf6b6e7233
< 2.0.31
MEDIUM 5.4 The PilotPress plugin for WordPress is vulnerable to unauthorized access to data and loss of data due to a missing capab… wordfence
6a762b7d-6b54-4933-a521-0435afb6f948 MEDIUM 5.4 The Supertext Translation and Proofreading plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
6a50e142-59f4-488b-8120-5bf505a9039d
< 5.1.0.2
MEDIUM 5.4 The Instant Images plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 5… wordfence
6a0a376e-ea3a-40ca-9341-f28f92e15e02
< 4.5.1
MEDIUM 5.4 The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability che… wordfence
69de7d93-b255-4d41-8680-9762ff632804
< 2.3.7
MEDIUM 5.4 The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is… wordfence
6975e84e-06ab-41b1-ae39-64685a878d15
< 7.3.5
MEDIUM 5.4 The Quiz And Survey Master plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and… wordfence
696d5fe3-1344-461b-a26f-e5099a836c33
< 1.23.8
MEDIUM 5.4 The WP Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘create_account_email'… wordfence
69654827-842f-483d-ae4c-b9c7ae271f82
< 4.3.2
MEDIUM 5.4 The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for ta… wordfence
69485409-8e91-4651-b9b8-69beb2364fa8
< 1.1.2
MEDIUM 5.4 The Activity Plus Reloaded for BuddyPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all… wordfence
← Prev 1078 1079 1080 1081 1082 1083 1084 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top