πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1097 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
15b4b132-1e27-454d-9ba0-9d1a552e1844
< 7.3.0
MEDIUM 5.4 The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This … wordfence
15b30ecb-e3ce-4092-841b-3a1b2553596a
< 2.8.10
MEDIUM 5.4 The Enhanced Media Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload functional… wordfence
158958ca-2e56-4102-9bcd-b235c7f49b65
< 7.4.0
MEDIUM 5.4 The FloristPress – Customize your Woo store for your Florist plugin for WordPress is vulnerable to unauthorized modifi… wordfence
15477c00-0764-4850-8bce-d65b6b1cbe4c
< 3.1.2
MEDIUM 5.4 The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The … wordfence
1518653c-e64d-4aba-b7f8-a928b8f2cbe3 MEDIUM 5.4 The Social Login WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5… wordfence
14c9dc08-6965-4a22-a97a-5afc8152887d
< 2.7.2
MEDIUM 5.4 The SportsPress plugin before 2.7.2 for WordPress allows XSS. wordfence
1410d37a-fa8d-41e1-bed7-1c1436b52a83
< 2.2.4
MEDIUM 5.4 The WPSchoolPress plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability ch… wordfence
13c07b63-f436-45ae-9c00-d1e593a32754
< 2.2.0
MEDIUM 5.4 The WP 2FA – Two-factor authentication for WordPress plugin for WordPress make it possible for attackers to disable ot… wordfence
139d4ec2-1147-4332-a56d-633890f32560
< 1.4.1.5
MEDIUM 5.4 The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
1398e296-9b20-4f8e-85f2-896888abc67e
< 1.2
MEDIUM 5.4 The Wordfence Theme My Login 2FA is vulnerable to 2FA brute-forcing in version up to, but excluding, 1.2. This allows un… wordfence
138e0a38-c922-44d1-9fe6-2439ec32cf39
< 1.0.42.2
MEDIUM 5.4 The Rank Math SEO plugin for WordPress is vulnerable to authorization bypass due to missing access controls on its "disa… wordfence
136d63c4-c985-413f-8d8b-b57e11d1d230
< 2.6.1
MEDIUM 5.4 The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to … wordfence
133a6fe8-e011-4749-b95d-e41a03a50aab
< 2.3.2
MEDIUM 5.4 The Debug Log Manager plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missin… wordfence
132a6661-c21b-4ba6-955a-2c905425de6a
< 1.4.5
MEDIUM 5.4 The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admi… wordfence
1322e229-5e0b-4c3d-ae96-e211a2831842
< 4.0.3
MEDIUM 5.4 The LearnPress - Export/Import Courses plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lea… wordfence
12a576ee-f8a9-4740-b87b-091a46970d53
< 2.1
MEDIUM 5.4 The WP Quick Post Duplicator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabili… wordfence
12643dd9-3b5e-45ea-9a64-a5b00c9202c8
< 7.7
MEDIUM 5.4 The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions … wordfence
121022ad-a569-4a80-96ee-c7911db81a30
< 4.7
MEDIUM 5.4 The eID Easy WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error parameter found in the ~/adm… wordfence
11b640a9-a031-4061-a4d2-93decd634acf MEDIUM 5.4 The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing t… wordfence
11795557-74c0-469a-9751-adc759f9214b MEDIUM 5.4 The Download canvasio3D Light plugin for WordPress is vulnerable to unauthorized access & modification of data due to a … wordfence
114ea55e-a3a4-420e-9202-73ebbd95d7b4
< 3.9.3
MEDIUM 5.4 Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions… wordfence
114cf149-e923-4e21-9eb0-e38941799304
< 2.0.1
MEDIUM 5.4 The Post View Count plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
10ede689-4434-47fc-bf94-ca6da678ae01
< 1.1.1.9
MEDIUM 5.4 The Easy Contact Form Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting did not properly sanitise th… wordfence
10409673-43dc-4c05-a996-120d753ebd6d
< 2.2.5
MEDIUM 5.4 The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data d… wordfence
101a3dfd-101e-4ae2-85d1-a6b3c9d6ca71
< 2.9.8
MEDIUM 5.4 The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter befo… wordfence
← Prev 1094 1095 1096 1097 1098 1099 1100 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top