🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1092 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
32bcff2d-e322-4c9c-b1c2-f07aa54faff9
< 5.9.10
MEDIUM 5.4 The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list' shortcod… wordfence
32aa1fdc-2fca-4486-b704-eabe4668361e
< 6.2.0
MEDIUM 5.4 The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add… wordfence
328438ba-128d-4094-83a5-bfd6e1616fa4
< 8.1.12
MEDIUM 5.4 The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the M… wordfence
3282244f-2b5f-4795-9f3f-461c4fd2e296
< 1.3.7
MEDIUM 5.4 The DW Question & Answer Pro WordPress plugin through 1.3.6 does not properly check for Cross-Site Request Forgery in so… wordfence
324fc401-04ca-4707-8727-b8c3a66f7fd6
< 2.7.0
MEDIUM 5.4 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
31dff395-c3ce-4ebe-8d38-5243fc4510d6 MEDIUM 5.4 The ImageMapper plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the… wordfence
315dbb77-d872-4cc4-bb4c-9d4763a6ff8f
< 2.4.2
MEDIUM 5.4 The LWS Tools plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.1. … wordfence
310afe02-3a51-4633-b359-65ae58d0c032
< 1.1.3
MEDIUM 5.4 The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized… wordfence
30fd2425-ee48-4777-91c1-03906d63793a
< 3.8.2
MEDIUM 5.4 The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
30e89955-9f2b-42e4-a7cf-558edd2e736c
< 7.0.4
MEDIUM 5.4 The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its… wordfence
30a89e75-2ab1-4e65-8646-b100efed5dbd
< 1.3.981
MEDIUM 5.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to External Entity Injection in all versions… wordfence
307e3e47-fac8-400d-9b90-b75b39ee14c3
< 1.1.16
MEDIUM 5.4 The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to unauthorized access due to a m… wordfence
306b23ee-7dcb-4281-a218-21168998c4b9
< 4.4.4
MEDIUM 5.4 The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
3044bd14-b914-4a2a-8e45-1129ac25a38a MEDIUM 5.4 The yPHPlista plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1… wordfence
2ff866c0-1b4c-4ad8-bde3-353ed0f44f42 MEDIUM 5.4 The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location. Edit: The affecte… wordfence
2fa2fcda-69f4-4095-b23c-6e6f1613adb0
< 1.0.7
MEDIUM 5.4 The HT Easy GA4 ( Google Analytics 4 ) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
2f760821-98d4-4154-a4ae-861283f991f8 MEDIUM 5.4 The wp tell a friend popup form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
2f4e5f34-c107-44da-9f73-e7b25f83e803
< 6.3.1
MEDIUM 5.4 The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in t… wordfence
2ed83916-3cf7-4fc6-a16f-45b40cedc721
< 2.8.8.3
MEDIUM 5.4 The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modi… wordfence
2e9d7776-aa96-47c8-9e31-5484ab65bc66
< 2.4.9
MEDIUM 5.4 The Discussion Board plugin for WordPress is vulnerable to Content Injection in versions up to, and including, 2.4.8 via… wordfence
2e9bee86-f491-4f68-b10b-051e0fb1a67b
< 4.4
MEDIUM 5.4 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due t… wordfence
2e78a4dd-af96-4317-aee4-9aae4fd6c066 MEDIUM 5.4 The Hide WP Toolbar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
2e6a78dc-9b67-4ab5-83f9-be82d05d3a13
< 1.2.4
MEDIUM 5.4 The Shoppable Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
2e45ac7f-faab-4004-8c1b-b9b68f9dfe4c
< 4.2.8
MEDIUM 5.4 The “Premium Addons for Elementor” WordPress Plugin before 4.2.8 has several widgets that are vulnerable to stored C… wordfence
2e2ab3b3-0d24-4b3d-8668-cc2bcf08d12f MEDIUM 5.4 The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'da… wordfence
← Prev 1089 1090 1091 1092 1093 1094 1095 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top