🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1093 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2dca6c29-9f05-4d82-90e3-834f1dd8005a
< 3.14.0
MEDIUM 5.4 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Ref… wordfence
2dc9c744-6ffb-4d7a-94ce-ba576d7b6d47 MEDIUM 5.4 The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
2db39ae2-6c44-4a4c-84de-9b7041bece37
< 4.8.9
MEDIUM 5.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Separator" ele… wordfence
2d5a9a2d-63d3-411c-af22-2829fd79c72b MEDIUM 5.4 The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within … wordfence
2d23541e-bb1c-4fcf-836b-28522a39b018 MEDIUM 5.4 The All Users Messenger plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and in… wordfence
2d0a822f-94b2-4875-b4b2-5c866555e3bd
< 3.1.7.1
MEDIUM 5.4 The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update A… wordfence
2cfe69ae-2d42-484e-9c35-672394219ec2
< 0.99
MEDIUM 5.4 An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permiss… wordfence
2cfbee75-13ef-49ad-9edd-f3077a033c1b MEDIUM 5.4 Multiple cross-site request forgery (CSRF) vulnerabilities in the Image Metadata Cruncher plugin for WordPress allow rem… wordfence
2cf5879f-82ae-41de-b220-aaec45c96c87
< 3.0.1
MEDIUM 5.4 The Feed Them Social plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘access_token’ param… wordfence
2cd509f7-100a-4f28-8d5a-b6b906456c52 MEDIUM 5.4 The WP-Eggdrop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.… wordfence
2c5f2dc8-67f7-4dbf-8631-f434522f1b53
< 4.1.8
MEDIUM 5.4 The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capa… wordfence
2c5cdc3f-eaa6-4d0b-9e75-5483c723e15a
< 2.6.9
MEDIUM 5.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' u… wordfence
2c26d6de-5653-4be8-9526-39b30cb61625
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… wordfence
2bff8dea-6971-47d4-bd2c-0821687033e5
< 2.33.4
MEDIUM 5.4 The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. Th… wordfence
2b1f068f-6473-4875-a990-dd4bf337e7b7
< 1.5.1
MEDIUM 5.4 The OpenPGP Form Encryption for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
2a9bf519-bc55-411b-836a-fb394e317396
< 1.5.5
MEDIUM 5.4 The Caldera Forms plugin for WordPress is vulnerable to Cross-Site Scripting via the "edit" parameter in versions up to,… wordfence
2a938325-45f5-455b-b2b7-e19e6e22cd0c MEDIUM 5.4 The Post State Tags plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
29b4c20b-486c-45d4-904f-561d6624d477 MEDIUM 5.4 The CRM: Contact Management Simplified – UkuuPeople plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
29358ea9-21b7-4294-8fc9-0d38e689cf53
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… wordfence
28fe3ec0-5e62-4a52-890d-e05b7d5bf531
< 1.15.6
MEDIUM 5.4 Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows chang… wordfence
28f0a927-a92e-45ab-8ef3-7a7c9368e1e4
< 2.5.4.4
MEDIUM 5.4 The Beaver Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the s… wordfence
28e16994-a03f-4b3a-9f45-e6b0a1334c98
< 5.9.1
MEDIUM 5.4 The Events Tickets Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … wordfence
28aae3d4-c4c4-4cda-9f4b-7f2ea58629aa
< 3.6.0
MEDIUM 5.4 The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3… wordfence
2821d32e-386b-4d6a-8079-b6b184d1d266
< 1.0.02
MEDIUM 5.4 Multiple cross-site scripting (XSS) vulnerabilities in the scr_do_redirect function in scr.php in the Shortcode Redirect… wordfence
27d579d5-a4d2-45f7-a7bb-8f384d851d7a
< 1.2.1
MEDIUM 5.4 The Force First and Last Name as Display Name plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… wordfence
← Prev 1090 1091 1092 1093 1094 1095 1096 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top