πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1241 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
afcbad6d-90ca-42cb-a69c-4e0bcc4606e0
< 6.3.6.3
MEDIUM 5.1 The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to limited arbitrary function calls via the 'registe… wordfence
219614b7-2394-490c-baf4-14a12249c4b5 MEDIUM 5.1 The Simple CSV/XLS Exporter plugin for WordPress is vulnerable to CSV injection in versions up to, and including, 1.5.8.… wordfence
f330bf36-0a39-40d6-a075-c87fdb9dc2da
< 3.1.15
MEDIUM 5.0 The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to … wordfence
ed507ac7-6732-4315-99dd-0a8636cc9cc3
< 3.0.0
MEDIUM 5.0 The Yumpu ePaper publishing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
ea26eb81-e6d1-4c6d-95f4-fd1b2d919632
< 4.5
MEDIUM 5.0 WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, wh… wordfence
e5b7b20d-d701-4146-b982-23d6be7a7ea0
< 2.6.45
MEDIUM 5.0 The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e… wordfence
cb5c5e82-d6e5-4237-958f-12fc4698e77e MEDIUM 5.0 The Resoto theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t… wordfence
c33ec58f-3e83-425a-9f0f-5e529be15e05
< 5.1.1
MEDIUM 5.0 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress … wordfence
c16e16dc-8888-4222-862f-a57a9f14e7f4
< 5.1
MEDIUM 5.0 The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versio… wordfence
b9c501a3-e092-453a-900f-60967b12c928
< 1.8.0
MEDIUM 5.0 The Cooked – Recipe Management plugin for WordPress is vulnerable to HTML Injection in all versions up to, and includi… wordfence
b062f72a-542c-4212-af83-4faefbf69bd7
< 2.3.1
MEDIUM 5.0 The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions… wordfence
aa2035ef-5251-49cc-a480-b6c167b5ef8c
< 3.5.4.3
MEDIUM 5.0 The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions… wordfence
9cd2b3fd-1bca-4611-9753-ccb57b0e36a4
< 1.2.59
MEDIUM 5.0 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordP… wordfence
97c100c3-8a96-4198-b38a-206268ff20ec
< 8.2.6
MEDIUM 5.0 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver… wordfence
92a3e622-b3b2-450e-82a7-0a942711e8c0
< 12.7
MEDIUM 5.0 The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Clickjacking via iframe injec… wordfence
8f24f7e2-2516-4f4d-955f-f3f6001cbce7
< 2.0.0
MEDIUM 5.0 The PhonePe Payment Solutions plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and i… wordfence
848f36de-c62a-45ee-b259-46dab73e4439
< 1.1.7
MEDIUM 5.0 The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to unauthorized modification of data… wordfence
7e0ef4a5-42d7-4cea-b19f-51917e3ee55f
< 5.3.6
MEDIUM 5.0 The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
689eb95b-2f72-4aa4-9f21-6ae186346061
< 1.6.27
MEDIUM 5.0 The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including… wordfence
66f392d0-d5fb-4a8c-b972-becfac6cf6e7
< 4.9
MEDIUM 5.0 The iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the srcdoc parameter in versions up to,… wordfence
58a4cb88-033e-48f4-b6fa-2a9754ab6a7f
< 4.10.0
MEDIUM 5.0 Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitra… wordfence
55ba8d6a-df38-4e24-afa4-6f82cb318c6b MEDIUM 5.0 The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all … wordfence
44276b28-9509-4f59-936c-fff2ae404076
< 2.7.2
MEDIUM 5.0 The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t… wordfence
42106dad-c568-4a79-af56-2d714dd8f487
< 20.8.2
MEDIUM 5.0 The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable… wordfence
3709465d-6d67-45bd-abb9-4875065b8129
< 4.3.18
MEDIUM 5.0 The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing c… wordfence
← Prev 1238 1239 1240 1241 1242 1243 1244 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top