ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1099 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0ada25c7-a636-45cd-b2ee-984b8f676011
< 4.8.7.2
MEDIUM 5.4 The All In One SEO Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
0aa925c8-7c65-45a4-95ca-a37290d74e86
< 4.0.1
MEDIUM 5.4 The Media Hygiene plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several… wordfence
0a49d74a-01a6-4bd9-bc93-0006f9fe9503
< 1.3.9
MEDIUM 5.4 The plugin BuddyForms Hook Fields for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, … wordfence
0a23e40d-9b9e-42ee-9319-c088e1024313
< 3.7.8
MEDIUM 5.4 The Fonts plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability… wordfence
0a13e87d-51cd-43b0-a658-900a174738fc
< 3.0.3
MEDIUM 5.4 The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… wordfence
09bdfade-85d0-4922-a83a-3e213adfa4ed
< 2.0.2
MEDIUM 5.4 The WooCommerce Product Stock Alert plugin for WordPress is vulnerable to unauthorized access of data due to a missing c… wordfence
095cc3dc-7a3e-473f-a762-de327c7ef28b
< 5.2.0
MEDIUM 5.4 The WordPress Slider Block Gutenslider plugin before 5.2.0 does not escape the minWidth attribute of a Gutenburg block, … wordfence
08c957fb-05e8-489e-846e-1afb0ca6750f
< 1.2.9
MEDIUM 5.4 The Gallery PhotoBlocks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.2.… wordfence
08c0ea6c-7e2f-482f-b30c-0e3bcd992159
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
0897d622-8e73-4bc0-a5f9-77bf8ddb4f93
< .51.1
MEDIUM 5.4 CVE-2014-7958: Cross-site scripting (XSS) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plug… wordfence
082b57a9-4703-4908-9119-47fc4034c35d
< 5.2
MEDIUM 5.4 The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanit… wordfence
0802e074-be51-4440-856f-e372e0821adb
< 2.7.0
MEDIUM 5.4 The Jeg Kit for Elementor – Powerful Elementor Addons, Widgets & Templates for WordPress plugin for WordPress is vulne… wordfence
07f7ef07-0f14-4b74-8d47-d5dece4954b0
< 14.13.4
MEDIUM 5.4 The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthori… wordfence
07b6aad4-fbaf-4c0c-b2b7-6e264a1afb9b
< 1.10.0
MEDIUM 5.4 The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, an… wordfence
078d06ad-555b-4de4-a032-d81440c7dfb5
< 4.0.2
MEDIUM 5.4 The Smart SEO Tool-WordPress SEO优化æ’ä»¶ plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
06b6c668-5f5d-4cf6-a3c6-4af755c72bca
< 1.5.4
MEDIUM 5.4 The Panda Pods Repeater Field for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'podid' parameter in… wordfence
06a92619-5281-414e-8846-be0db38df89d MEDIUM 5.4 The Appointment Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
06a7e784-49c3-44fd-882b-c76ab8d871e2
< 20220216
MEDIUM 5.4 Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the cha… wordfence
067a5f6c-7ad1-49ac-a581-b50fa89a5f39
< 4.3
MEDIUM 5.4 The Admin Columns Free WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1, rendered input o… wordfence
06752651-4c7f-48dd-989c-c254c6ca7ae4
< 2.4.2
MEDIUM 5.4 The Pronamic Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the description field in … wordfence
0615d1be-f9fa-45b3-9d5b-3ad1f36be8e1
< 1.1.8
MEDIUM 5.4 The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modifi… wordfence
060f31ab-cfa4-4ca8-846a-de76848b28fb
< 4.4
MEDIUM 5.4 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellati… wordfence
05f175e6-08a9-4199-948c-5bd8b3caaa39
< 4.6
MEDIUM 5.4 The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
05b15f33-0f95-458f-8c21-16c0dd98c8bc
< 2.4.6
MEDIUM 5.4 The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions … wordfence
0594ed62-0a41-4819-89b8-ea31afbcac73
< 1.1.14
MEDIUM 5.4 The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modificati… wordfence
← Prev 1096 1097 1098 1099 1100 1101 1102 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top