πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1101 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ff840236-4368-45aa-a9a3-7e02f20783d8
< 6.4.3
MEDIUM 5.3 The YOP Poll plugin for WordPress is vulnerable to IP spoofing via the X-Forwarded-For header in versions up to, and inc… wordfence
ff7d09d1-bbc7-417c-bb3c-30f9ffe49522
< 2.10.1
MEDIUM 5.3 The Falcon – WordPress Optimizations & Tweaks plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
ff6ebf45-4617-44dd-94d8-28aa8bc1609b
< 0.19.2
MEDIUM 5.3 The If Menu plugin for WordPress is vulnerable to unauthorized modification of the plugin's license key due to a missing… wordfence
ff4ae5c8-d164-4c2f-9bf3-83934c22cf4c
< 3.0.4
MEDIUM 5.3 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
ff2f1261-3c61-4a0f-a7db-8e9b28b9af27
< 2.0.2
MEDIUM 5.3 The Formidable Forms Signature Online Contract Automation plugin for WordPress is vulnerable to Insecure Direct Object R… wordfence
ff2673c5-82f6-4022-a58e-f9728f577223
< 2.0.12
MEDIUM 5.3 The JetPopup plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
ff1e4da0-916c-4d0e-a68b-16b6851b99a0 MEDIUM 5.3 The WP Clone any post type plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
ff1b8d09-974a-4735-8b63-15084412090d
< 2.7.8.4
MEDIUM 5.3 The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… wordfence
fef475f8-7610-4412-b061-0be069ad7fad
< 2.14.23
MEDIUM 5.3 The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Infor… wordfence
feeb70e4-b602-40ce-bdeb-d947c6b6784d
< 5.1.9.3
MEDIUM 5.3 The RegistrationMagic plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 5.1.9… wordfence
feb915f4-66d6-4f46-949c-5354e414319b
< 3.3.04
MEDIUM 5.3 The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to im… wordfence
feb63b10-fe23-4f89-9ef3-0a61b4190320
< 3.0
MEDIUM 5.3 The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and inclu… wordfence
fea293db-935b-4a06-83ee-d57bf5f307cd
< 1.2.51
MEDIUM 5.3 The News Magazine X theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
fe97e970-d5a3-4a71-af38-37f9ab57067d MEDIUM 5.3 The QuadLayers TikTok Feed plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
fe8816d8-1687-4a3c-9f2a-23f21d679cc5
< 3.2.0
MEDIUM 5.3 The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to Sensitive Info… wordfence
fe737eb1-4b9f-4efb-ad34-6c0be4d66043
< 6.8.6
MEDIUM 5.3 The AI Content Writer, Autoblogging, Youtube Subtitle to Article – SEO Help plugin for WordPress is vulnerable to unau… wordfence
fe685a64-a84c-4d29-b002-05d40f540391
< 1.1.4
MEDIUM 5.3 simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sen… wordfence
fe684f43-8442-4b29-84a8-da8c6863e62b
< 4.0.2
MEDIUM 5.3 The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct… wordfence
fe4c20d6-cf38-45c3-9733-ff1fbe4908f4
< 2.0.0
MEDIUM 5.3 The Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress plugin for WordPress is v… wordfence
fe4171b9-b17e-4e6e-9ab4-4b1b125e8950
< 1.1.0
MEDIUM 5.3 The Lana Email Tester plugin for WordPress is vulnerable to Cross-Site Request Forgery and unauthorized Mail Relay in ve… wordfence
fe391ac9-e3ea-48b3-8ffe-243972ce89f6
< 2.0.11
MEDIUM 5.3 The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… wordfence
fe324d4d-eb52-4eeb-ad91-072a6e84d9ba
< 1.0.1
MEDIUM 5.3 The Accessiy By CodeConfig Accessibility plugin for WordPress is vulnerable to unauthorized page creation due to missing… wordfence
fe2cfc96-63f4-4e4b-bf49-6031594a4805
< 2.7.14
MEDIUM 5.3 The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-… wordfence
fe10f68d-cab7-447a-ad91-005ca2230250
< 1.3.9
MEDIUM 5.3 The Education Zone theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
fde0ab44-a354-4cbe-8548-0e5c08529082
< 5.1.9.3
MEDIUM 5.3 The RegistrationMagic plugin for WordPress is vulnerable to content injection in versions up to, and including, 5.1.9.2.… wordfence
← Prev 1098 1099 1100 1101 1102 1103 1104 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top