πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1098 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0f01ee24-544b-45cb-9cf3-7db8263d8e54
< 1.2.0
MEDIUM 5.4 The WP Directory Kit plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.1.9. This i… wordfence
0e7e7c70-4d07-4550-9cf8-5135b87b67ca
< 2.2.97
MEDIUM 5.4 The Accordion plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missin… wordfence
0e4fec06-13d3-49ce-afe5-8dca15cf1f0a
< 2.5.15
MEDIUM 5.4 The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins. wordfence
0e475e02-494a-4ad0-a83c-d027c3a32989
< 3.9.5
MEDIUM 5.4 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized attachment del… wordfence
0e240f4b-dfdf-4954-af39-34e24a05a2ed
< 5.22.3
MEDIUM 5.4 The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users … wordfence
0e05142e-04a3-483e-a4af-035df3609b9d
< 1.2.7.2
MEDIUM 5.4 The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings. wordfence
0dfe0947-5790-49ba-aa3d-6bc61c12b355
< 1.4.0
MEDIUM 5.4 The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capabi… wordfence
0dc20a45-15b5-42d3-a484-988a394ee658
< 2.17
MEDIUM 5.4 A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with bas… wordfence
0dbed7a2-730d-42f2-9d57-3f07900d33e3
< 1.4
MEDIUM 5.4 The Video Player for YouTube WordPress plugin before 1.4 does not sanitise or validate the parameters from its shortcode… wordfence
0da6a080-260f-4b19-a32c-453d2781389a
< 8.3.5
MEDIUM 5.4 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Str… wordfence
0d9cea4e-b619-4935-bb7c-a64ddf52d480
< 7.0.18
MEDIUM 5.4 The Stylish Price List plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing… wordfence
0d943691-66cf-4018-9eb6-5f20db0a95a9
< 3.4
MEDIUM 5.4 The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field. wordfence
0d20bae1-5a94-402b-9001-725b433c9d55
< 1.6.7
MEDIUM 5.4 The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & C… wordfence
0d017b2c-1e15-401a-ae57-4653ca41b7e6
< 4.0.2
MEDIUM 5.4 The MainWP Buddy Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 4… wordfence
0cde6b5b-f760-467b-940f-06a1f983ddc4
< 3.4.1
MEDIUM 5.4 A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had bui… wordfence
0cd72420-dca1-455d-92a6-a178b4b26eab
< 3.5.26
MEDIUM 5.4 The ConvertPlug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
0cd6474f-72e1-4ec2-a056-3c05a0dfa173
< 4.8.9
MEDIUM 5.4 The Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.8… wordfence
0ccf1582-7d3d-4ca0-b241-d6deaa79a994 MEDIUM 5.4 The Qubely plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
0ca9e920-3c7a-4991-8c24-2e55c4f4767c
< 1.4.6
MEDIUM 5.4 The Motors – Car Dealer & Classified Ads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
0c829230-7527-4ae2-a5c8-db2371e4cd5a
< 3.8
MEDIUM 5.4 The Amministrazione Aperta WordPress plugin through 3.7.3 does not validate the open parameter before using it in an inc… wordfence
0c173356-7228-4253-bb28-2c2e11af76fd
< 3.9.8
MEDIUM 5.4 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course… wordfence
0be428ae-40ae-4cc0-82ad-d121b6d2d27e
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… wordfence
0afcfe15-2d7d-4c96-a408-28f35577a927
< 3.6.10
MEDIUM 5.4 The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of d… wordfence
0af6e55d-def9-4bb1-ade9-56aa8184961c
< 6.0.1
MEDIUM 5.4 The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Cross-Site Request Forger… wordfence
0aeb63e7-a24d-4d76-a8c7-f082dad87a55
< 2.0.9
MEDIUM 5.4 The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themify_post_… wordfence
← Prev 1095 1096 1097 1098 1099 1100 1101 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top