ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1090 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3f5d3585-19fe-4e85-87d0-7f4c62944146
< 8.1.6
MEDIUM 5.4 The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
3f4ac2c0-2c22-431c-b892-b4bf6a7319ce
< 3.9.21
MEDIUM 5.4 The CM Tooltip Glossary plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
3ef8bf84-768f-4ef1-8037-4e51ccc20c83
< 2.2.5
MEDIUM 5.4 The Simple Staff List plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to … wordfence
3ed93c5c-38bb-4e84-8fe8-03dd75b4d9f3
< 1.2.2
MEDIUM 5.4 The LuckyWP Scripts Control plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
3ec54ec6-0ff1-4290-85d0-d691a1832627
< 2.1.15
MEDIUM 5.4 The weDocs plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.1.14. This … wordfence
3ec4e870-dd0f-4ec5-a03c-da47e6c1ef61
< 2.8.5
MEDIUM 5.4 The bbPress Login Register Links On Forum Topic Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
3ec2f684-fa04-4201-a826-1eed328821de
< 2.76
MEDIUM 5.4 Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress… wordfence
3ebc0e28-ced8-4fb0-818d-1452faf9660d
< 3.4.12
MEDIUM 5.4 The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Paginat… wordfence
3e85adbd-7e82-4949-916b-20aba1f97bf1
< 2.7.1
MEDIUM 5.4 The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1… wordfence
3e394ee2-13c1-4b04-a8a5-4642f1794d59
< 1.6.5
MEDIUM 5.4 The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing c… wordfence
3e0231cf-7de7-4fe7-a0fe-20657f727fef MEDIUM 5.4 Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 is affected by: Cross Site Scripting (XSS) via the 'Recal… wordfence
3db1d9a0-ea68-4979-a36d-864c649f7aca
< 3.1.2
MEDIUM 5.4 The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPre… wordfence
3dacef70-a881-400e-b9f7-c0a815cf624a MEDIUM 5.4 The Tiempo.com plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.1.2.… wordfence
3d4b9f07-a4a0-4cbd-a147-281570bc7f4a
< 3.8
MEDIUM 5.4 The Auto Publish for Google My Business plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
3d4a938a-044b-4991-bc4c-db9e15210f06
< 29.1.6
MEDIUM 5.4 The Snow Monkey theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2… wordfence
3d0ecffe-8543-4d82-a1cc-f2474499f373 MEDIUM 5.4 The SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue plugin for WordPress is vulnerable to Stored Cross-S… wordfence
3cf00aef-427b-4256-9cbd-83c8e5059ecf
< 4.0
MEDIUM 5.4 WordPress Core before 4.0 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, whic… wordfence
3c99aab5-a995-44ae-bc14-09f73e6b22c5
< 4.5
MEDIUM 5.4 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modif… wordfence
3c85fa64-4761-4b92-bd4f-7c220cf18288
< 2.8.34
MEDIUM 5.4 The Urvanov Syntax Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
3c6bbdcd-9b08-4c17-9a87-e06baa4cca1c MEDIUM 5.4 The Stock in & out WordPress plugin through 1.0.4 has a search functionality, the lowest accessible level to it being co… wordfence
3c5bde0e-3138-4995-92ae-6deaf6b7be5b
< 2.7.10
MEDIUM 5.4 The Groundhogg plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missi… wordfence
3c52ca89-4f13-41da-bc10-80d212c6219c
< 3.2.4
MEDIUM 5.4 The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
3c3091eb-a2e7-4fc2-9f5c-5d6d582bbb89
< 1.13.60
MEDIUM 5.4 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not es… wordfence
3bc48d4d-eeee-47f7-be5e-0d6a43473aa0 MEDIUM 5.4 The Progress Bar Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upl… wordfence
3bad1d0d-3817-4c7f-a012-5a85b577781e
< 3.1.13
MEDIUM 5.4 The Nextend Social Login and Register plugin for WordPress is vulnerable to a self-based Reflected Cross-Site Scripting … wordfence
← Prev 1087 1088 1089 1090 1091 1092 1093 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top