πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1095 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
21b6748a-43fb-4326-ac1f-d3ae2a6700f2 MEDIUM 5.4 The Slippy Slider – Responsive Touch Navigation Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
200baebd-7fd1-4df6-99ab-71f999b4e85a
< 1.0.13
MEDIUM 5.4 The Bosa Elementor Addons and Templates for WooCommerce plugin for WordPress is vulnerable to unauthorized access of dat… wordfence
1fc447bc-841c-443f-9949-a0d852762fd9
< 3.12.4
MEDIUM 5.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi… wordfence
1fc3f65e-5fbe-403b-b7cd-dde16a7e5778
< 4.1.39
MEDIUM 5.4 WordPress Core is vulnerable to arbitrary shortcode execution in versions up to, and including, 6.3.1 due to a lack of i… wordfence
1f9b02c1-2cd7-48ee-b568-4c42bc0ded96
< 3.5
MEDIUM 5.4 A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an appl… wordfence
1f8f8378-676e-455a-aaad-b80c1a4dc717
< 2.4.2
MEDIUM 5.4 The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a ro… wordfence
1f7e9eb5-e222-43fa-a14f-b9cbced6b8f5
< 6.3.5
MEDIUM 5.4 The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthoriz… wordfence
1f545c20-5be1-42bc-9268-640590ee4bf2 MEDIUM 5.4 The WordPress Mobile Pack plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
1f528c89-2b8c-4750-b9eb-47ebd8c1630e
< 2.6.5
MEDIUM 5.4 The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capabi… wordfence
1f4bd246-5632-4701-aa57-3855e73e6eb6
< 2.0.6
MEDIUM 5.4 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks … wordfence
1ededa54-654f-48dc-87d5-7321e041e6fb MEDIUM 5.4 The Whizzy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, … wordfence
1ebb6ebe-3a66-4ad8-9bba-c09354810159
< 2.1.0
MEDIUM 5.4 The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in vari… wordfence
1e6c1e98-72a2-4e74-bfd4-4054187d4d19
< 6.2.1
MEDIUM 5.4 The WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an insufficient capability check on th… wordfence
1dffbb2d-69d1-495c-8c96-64c5fd878fcd
< 2.9.12
MEDIUM 5.4 The Stock Quotes List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in ve… wordfence
1de6c0d9-efa8-4c86-9d57-7aa92a0eda96
< 3.0.5
MEDIUM 5.4 The Cliengo – Chatbot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
1d5d2217-306c-4ea2-9727-5c02f7d67c2d
< 1.1.11
MEDIUM 5.4 The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
1cf2739f-9001-409a-9b7f-024931729da3
< 3.9.11
MEDIUM 5.4 The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perfor… wordfence
1c866d8d-399c-4bda-a3c9-17c7e5d2ffb8
< 3.3.1
MEDIUM 5.4 The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf' shortco… wordfence
1c8152c5-7d72-48a1-9140-8b0341c86023
< 3.5.1
MEDIUM 5.4 The Wbcom Designs – BuddyPress Activity Social Share plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
1c75edd2-fc38-48b1-b58c-1d19c95c3db8 MEDIUM 5.4 The WP Forms Puzzle Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
1c6a1956-73aa-4ac3-ae1c-ef5f62bad718 MEDIUM 5.4 The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthoriz… wordfence
1c5108f3-d80c-4646-8d40-3bdd1361c6ab
< 1.4.6
MEDIUM 5.4 The Accordion and Accordion Slider plugin for WordPress is vulnerable to authorization bypass in all versions up to, and… wordfence
1c40c28f-554f-42d0-9f6d-a899d8f61519
< 10.0.2
MEDIUM 5.4 The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versio… wordfence
1c387b07-baf6-4c62-943e-4bd121160ceb
< 1.7.25
MEDIUM 5.4 The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
1b660260-e335-4be0-a266-0cdc9a4d7504
< 1.7.8
MEDIUM 5.4 The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJA… wordfence
← Prev 1092 1093 1094 1095 1096 1097 1098 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top