🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1083 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
63f1c60f-8f72-4c99-92af-340c67b7411f MEDIUM 5.4 The Logaster Logo Generator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check… wordfence
63bced7f-89ec-4c52-9e58-63ef2d311b31
< 2.7.1
MEDIUM 5.4 The Catch Web Tools plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the … wordfence
63b272f5-08d1-4c5b-a500-d919903793b7
< 3.4.1
MEDIUM 5.4 The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, … wordfence
63779ab7-ba8b-459d-beb3-a32faf8f4394
< 4.4.4
MEDIUM 5.4 The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_su… wordfence
636c9d92-ee62-499d-8d73-33cd63bb5af8
< 3.5.1
MEDIUM 5.4 The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
63590140-9723-4e91-884c-f2b11b67eb8d
< 3.7.30
MEDIUM 5.4 WordPress before 5.2.3 allows XSS in post previews by authenticated users. wordfence
6356e226-a449-4cd0-be60-2a1c9c70aa59
< 1.1.123
MEDIUM 5.4 The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 d… wordfence
6346024c-61d5-4f73-b7f2-3a8fd3fb838e
< 3.7.6
MEDIUM 5.4 Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as… wordfence
62ed278c-f914-4edd-aba1-4aaa099a869f
< 5.3.8
MEDIUM 5.4 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… wordfence
62b56928-7125-4211-b233-07b5b51881c1
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
62ac2725-0071-4a7d-8561-256e6a232de3 MEDIUM 5.4 The Tiempo.com plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.1.2.… wordfence
6231e47e-2120-4746-97c1-2aa80aa18f4e
< 3.93.0
MEDIUM 5.4 The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
61d3cb97-f12b-4480-88fc-2bdcbf4cdae3
< 1.2
MEDIUM 5.4 The Chative Live chat and Chatbot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
61c5253c-0c0c-4026-bf04-ea5bb2985358
< 3.8.1
MEDIUM 5.4 The WCFM Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inclu… wordfence
61b590f5-7854-42f7-b5e2-e6feaaf03a73
< 8.7.1
MEDIUM 5.4 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of d… wordfence
617dcc0e-e212-4da0-8918-e55e6b3895fa
< 7.3.4
MEDIUM 5.4 The Zotpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.3.… wordfence
61799fbc-05dc-4de9-90f9-8712ba554607
< 2.10.0
MEDIUM 5.4 The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on th… wordfence
616c8ab8-3200-41fb-9d31-5d36873742cb
< 1.1.0
MEDIUM 5.4 The Change WP Admin Login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CS… wordfence
615d35dd-a92e-4910-b0fc-ac0a7d03741a
< 2.2.19
MEDIUM 5.4 The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_e… wordfence
60c2e8eb-d01b-44f2-8e0d-009ff00887fd
< 1.0.47
MEDIUM 5.4 The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any cu… wordfence
609d9ecf-4f91-4a78-ad8c-22e436c000ed
< 2.3.2
MEDIUM 5.4 The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several wi… wordfence
60830ed8-3ab8-44e8-899c-7032a187da8b
< 1.8.1
MEDIUM 5.4 The WP Duplicate Page plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability … wordfence
60493635-b1b0-4e76-8f73-16c223d7b4d7
< 1.1.35
MEDIUM 5.4 The Header Footer Code Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
5ff589ec-756d-4183-8bb8-61dae9be7c5d
< 2.9.2
MEDIUM 5.4 The Elements kit Elementor addons plugin for WordPress is vulnerable to unauthorized admin notice dismissal due to a mis… wordfence
5fa2ec9e-2859-4a96-9e33-9e22d37e544f
< 3.8.3
MEDIUM 5.4 The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the … wordfence
← Prev 1080 1081 1082 1083 1084 1085 1086 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top