πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1094 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
27857a17-8cf0-40b3-894f-8dd7cf5108dd MEDIUM 5.4 The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
2764b360-228d-48c1-8a29-d3764e532799
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… wordfence
27337cf2-18a0-4f26-a674-3ab2003b4838
< 3.3
MEDIUM 5.4 The WooCommerce Anti-Fraud plugin for WordPress is vulnerable to Insecure Direct Object Reference (IDOR) due to insuffic… wordfence
272c6fbb-bc85-46d9-b139-87534b2a0842
< 4.1.6
MEDIUM 5.4 The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
2719739a-90dc-470b-9270-8578e0cead59
< 3.7.7
MEDIUM 5.4 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthor… wordfence
26d9dfc7-151c-4b32-9ae4-3085d08f137c
< 1.8.1
MEDIUM 5.4 The Embed Privacy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embed_privacy_opt_… wordfence
26bfef74-214f-4257-afc7-730e82e80946
< 2.7.4.3
MEDIUM 5.4 The Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Icon Widget 'fl_builder_dat… wordfence
262dcea7-3ac4-43ee-90d7-91f200c3496c
< 6.5.5
MEDIUM 5.4 The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Si… wordfence
26253942-7948-4016-947d-8c98f01525ab
< 3.0
MEDIUM 5.4 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulner… wordfence
261a1bf0-a147-48c8-878e-f9b725ac74d8
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
25a80b0b-2636-45c1-92e5-bd62c8a4ab20
< 1.0.49
MEDIUM 5.4 The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any cu… wordfence
25200656-a6a2-42f2-a607-26d4ff502cbf
< 3.3.1
MEDIUM 5.4 The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_last_nam… wordfence
2497837d-dec6-4a1d-be88-5c0e659eeb46
< 2.6.8
MEDIUM 5.4 TheKraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability chec… wordfence
241da621-b892-4263-8409-a40ac5a1ade3 MEDIUM 5.4 The Add Local Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
24142bf8-15e7-460d-83a3-52dc57537498
< 6.5.2
MEDIUM 5.4 The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
23e47daa-79e7-4ed3-a88a-0f090e9aa277
< 6.9.1
MEDIUM 5.4 The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
23a94578-f395-4ec1-8a08-52ca233cc832
< 1.2.4
MEDIUM 5.4 The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF checks in the meks_save_… wordfence
2372e851-97dd-449b-b356-f43f6fd409df
< 1.0.4
MEDIUM 5.4 The Pixel WordPress Form BuilderPlugin & Autoresponder plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
230b6a10-1505-4f66-ba98-df6257a80668
< 1.9.6
MEDIUM 5.4 MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership versions prior to 1.9.6 are vulnerable to Cros… wordfence
2304e4dc-0dc6-4ded-b8e6-8d76d70f63d7
< 1.7.7
MEDIUM 5.4 The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
22b3ee70-7ba6-4f8a-add4-3c7f4765b3d1
< 3.7.10
MEDIUM 5.4 Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js i… wordfence
229490c3-d820-4831-b105-a429512c2c60
< 7.2.8
MEDIUM 5.4 The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modific… wordfence
22506d45-40db-47c4-91b2-ab4f49703bf9
< 2.7.11.1
MEDIUM 5.4 The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.11… wordfence
22420c2d-788c-4577-ae54-7b48f6063f5d
< 2.6.1
MEDIUM 5.4 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to HTML Injection in all versi… wordfence
21cc3f71-7591-4111-a58a-d863df74587f
< 5.6.6
MEDIUM 5.4 The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forger… wordfence
← Prev 1091 1092 1093 1094 1095 1096 1097 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top