πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1100 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
053b72c6-07bb-4e9f-ae25-da4bce91ae6e
< 2.0.26
MEDIUM 5.4 The Simple SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.25… wordfence
04a79a78-a6d3-40ef-9b26-8e2e00534b7a
< 4.2.9
MEDIUM 5.4 The ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.8. Th… wordfence
0488a421-e725-4b64-94ee-3a81f4bc5451
< 3.8.8
MEDIUM 5.4 The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Open Redirect i… wordfence
0482d9c6-aa74-4d47-885c-17f14b38be6f
< 2.3.4
MEDIUM 5.4 The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editi… wordfence
04708871-a8eb-4afe-981f-aab965f6ea16 MEDIUM 5.4 The Metrika plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. … wordfence
04601634-d707-44a7-9b5f-46c4b9687469
< 7.2.1
MEDIUM 5.4 The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the buddy… wordfence
040005bc-bdc3-4085-8192-cd0a7e38fee0 MEDIUM 5.4 The WP Bootstrap Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on… wordfence
03eed366-c018-44b9-bb72-56911e9957b8
< 1.4.6
MEDIUM 5.4 The Robots.txt optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
0388853e-4bf8-4627-876a-b842e7016de3
< 8.9.1
MEDIUM 5.4 The MonsterInsights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles and pages in versi… wordfence
036cf299-80c2-48a8-befc-02899ab96e3c
< 2.7.15
MEDIUM 5.4 The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored… wordfence
031c31b2-6e27-47bb-9f63-2bbaa1edbbb2
< 11.0.7
MEDIUM 5.4 The PowerPress plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 11.0.… wordfence
02649a9e-036a-47fe-ab1a-26caf4f2be27
< 5.5.5
MEDIUM 5.4 The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
0254cd1b-f8f6-400e-a48e-81bd553fe8d1
< 1.2.6
MEDIUM 5.4 The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable … wordfence
01f60df7-0602-4a00-9905-a91348811dfe
< 3.4.5
MEDIUM 5.4 The Popup box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ays_pb_tab' parameter in ver… wordfence
01dfb46a-5721-415f-8a92-e874c46b8e47
< 2.2.0
MEDIUM 5.4 The April's Call Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
01cfd7db-f62d-4110-b9a4-49ff1e4e5e68
< 5.0.4
MEDIUM 5.4 The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to authorizati… wordfence
019f4735-a25c-46c7-8a7d-55351197bdf2
< 2.2.0.7
MEDIUM 5.4 The Easing Slider plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.2.0.6 v… wordfence
01889c7b-f47b-4caf-8e35-4f8af188426e
< 4.1.1
MEDIUM 5.4 The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed… wordfence
0131921b-6f60-4da1-b5d9-d44a33d35cae
< 2.0.1
MEDIUM 5.4 The JS Job Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
012e019f-9146-45bc-b4d7-aa724dbebdc6
< 2.2.3
MEDIUM 5.4 The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the… wordfence
00d69e80-36fa-4b74-8138-56c0bf576e44
< 2.0.7
MEDIUM 5.4 The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intende… wordfence
00cb5ce9-cca2-4e41-8d00-1d2ca7770dce
< 1.5.63
MEDIUM 5.4 The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter. wordfence
007af51b-95b5-4b12-9f74-abf31f6de341
< 3.3.5
MEDIUM 5.4 The Real Estate 7 theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.… wordfence
ffe32701-4cfe-42f1-bf00-8de653d6568a
< 1.5.0
MEDIUM 5.3 The Ultimate Maps by Supsystic plugin for WordPress is vulnerable to unauthorized access in all versions up to 1.5.0. Th… wordfence
ffdb95ac-6b22-44a9-bd5c-b802a2d908d7
< 4.10.1
MEDIUM 5.3 The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up … wordfence
← Prev 1097 1098 1099 1100 1101 1102 1103 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top