πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1086 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
54f6a790-7cff-4910-a481-48ae13ba57c8
< 3.0.10
MEDIUM 5.4 The Crowdsignal Dashboard plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including, 3… wordfence
540b2888-16fe-4791-8d08-f7772f71d511
< 1.10.0
MEDIUM 5.4 The Lightbox slider – Responsive Lightbox Gallery plugin for WordPress is vulnerable to PHP Object Injection in all ve… wordfence
53a08b59-b7e0-419a-bfc3-528bcddb1ac2
< 3.5.1.34
MEDIUM 5.4 The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing cap… wordfence
53459a4d-6ffd-46bf-926a-761db4cfb50c
< 4.0.2
MEDIUM 5.4 The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which c… wordfence
52b1d515-4965-4ab9-80dd-526b4ebeb3a9
< 2.4.10
MEDIUM 5.4 The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contribut… wordfence
5289f7a5-7b7b-4627-a313-b8480f88b158
< 2.6.0
MEDIUM 5.4 The leenkme plugin before 2.6.0 for WordPress has stored XSS via facebook_message, facebook_linkname, facebook_caption, … wordfence
526aa2e5-06bd-4b4c-a331-315f8ab37858
< 5.02
MEDIUM 5.4 The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
525cb51c-23f1-446f-a247-0f69ec5029d8
< 3.13.3
MEDIUM 5.4 The Elementor plugin for WordPress is vulnerable to the creation of emergent resources due to insufficient input validat… wordfence
524452b9-e617-4434-a23f-6026b6f55eeb MEDIUM 5.4 The Polo Video Gallery – Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validat… wordfence
520598d7-863f-4bf3-ba74-fa9b2cc32767
< 1.40.4
MEDIUM 5.4 The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an… wordfence
51fab95e-336d-4544-8b8e-c4e9002321ec
< 4.10.31
MEDIUM 5.4 The Premium Addons Pro for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maps widg… wordfence
51cfe955-f854-4f88-a009-93f92ae13d86
< 5.16.2
MEDIUM 5.4 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data and modificati… wordfence
51b88442-3961-42e2-8ff4-7726819a7f0f
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
51b6c73d-fd4f-4469-9859-fbae61b5924c
< 1.4.5
MEDIUM 5.4 The WP Super Cache plugin for WordPress is vulnerable to Authenticated File Deletion in versions up to, and including, 1… wordfence
51810981-5d2b-471b-b602-35809e281a0b
< 3.1.1
MEDIUM 5.4 The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
5122800d-f274-4129-84d4-02380269502c
< 1.3.975
MEDIUM 5.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form … wordfence
50b26952-bf59-4236-93b4-6b4928609c15
< 2.7.16
MEDIUM 5.4 The WPFunnels plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and including, 2… wordfence
50a89ad1-a3d0-49e3-8d2e-4cb81ac115ba
< 7.0.1
MEDIUM 5.4 The WP Shortcodes Plugin β€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
50726c57-8d42-4143-9e75-d30513d8d0e2
< 2.10
MEDIUM 5.4 The Sublanguage plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the multi… wordfence
505e9ba4-a19c-4d51-8ba7-4891bbac603e
< 1.12
MEDIUM 5.4 The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contrib… wordfence
50542e5e-da66-4223-a6bf-dc9381687ddd
< 1.2.6
MEDIUM 5.4 The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable… wordfence
5015cfe7-9e5c-4745-b6c3-60e4aa99672d
< 3.7.5
MEDIUM 5.4 The Master Slider plugin for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings … wordfence
4fdf49e7-c89e-4b05-9236-ca28e715bc4a
< 3.3.2
MEDIUM 5.4 wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to… wordfence
4eff91bd-efc2-4e54-b871-df567ca99bca
< 2.6
MEDIUM 5.4 Multiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin … wordfence
4eff0dfd-f7e6-4f5f-b1c8-00f69fa0df78
< 5.3.1
MEDIUM 5.4 The MyRewards plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several fun… wordfence
← Prev 1083 1084 1085 1086 1087 1088 1089 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top