πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1345 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
01bd8a24-5580-4b16-94b3-c231d5fe7a01
< 2.3.0
MEDIUM 4.4 The WooDiscuz – WooCommerce Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti… wordfence
01a70f60-9207-48a9-9ba2-7a29813fa934 MEDIUM 4.4 The Lenix scss compiler plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
014ccad9-a836-4a40-92d3-8c3320fbead8
< 2.0.0
MEDIUM 4.4 The PDQ CSV plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to,… wordfence
00dc3911-c29e-4f4f-973c-8e4da5dd0e35
< 3.8.18
MEDIUM 4.4 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
00bb89b7-e8f3-4ffc-8086-34f70a66e641 MEDIUM 4.4 The Login-Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8… wordfence
0092f02d-ec3a-4a11-bad9-67714d3d976e
< 2.9.1
MEDIUM 4.4 The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
007d8935-974f-4bc4-833e-25ca50a50a29
< 4.7.2
MEDIUM 4.4 The Button contact VR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… wordfence
005032e2-b5aa-44d8-855f-2aceee9e740f
< 20240516
MEDIUM 4.4 The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Store… wordfence
001f25c8-d9b5-4b24-9cd1-be726916079c
< 3.59.3
MEDIUM 4.4 The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Stored Cross-S… wordfence
0008b460-0c28-4e72-9c87-eda91989e39a
< 0.3
MEDIUM 4.4 The Site Favicon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
fffa6c31-8da0-48d7-b603-64f50950787b MEDIUM 4.3 The Peer Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
ffee6564-2718-4461-b481-cbf0e204a04d
< 3.8.8
MEDIUM 4.3 The Ultimate Dashboard – Custom WordPress Dashboard plugin for WordPress is vulnerable to unauthorized modification of… wordfence
ffdf34bb-a887-444c-8a76-12901fed6662
< 4.3.3
MEDIUM 4.3 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP… wordfence
ffc5408c-ca31-4cb6-8cb5-063acbbad01e
< 1.2.2
MEDIUM 4.3 The News Kit Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to… wordfence
ffb8a285-43c6-4956-ad37-484269463b2d
< 6.1.7
MEDIUM 4.3 The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized modificat… wordfence
ffa54d4e-a633-48a4-83c0-33b7cbd2229a
< 3.3.25
MEDIUM 4.3 The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
ffa3b053-07cd-4c5f-b9d1-016cbca4b171
< 2.0.7
MEDIUM 4.3 The Siteimprove plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.6… wordfence
ff8e8889-ec02-4b8d-9509-2c6335fdd9a4
< 2.2.0
MEDIUM 4.3 The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Information Exposure … wordfence
ff850f88-6e89-48dd-ad70-dda4018c22fc
< 2.8.4
MEDIUM 4.3 The WooCommerce Canada Post Shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
ff79e4b4-f3f1-4a7f-97f5-09bb3fc9c0c0
< 1.1.0
MEDIUM 4.3 The YITH Slider for page builders plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
ff77ffea-6b43-4875-965a-a72d761e93f7
< 3.21.1
MEDIUM 4.3 The Order Delivery Date for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
ff6c0ce5-b98e-4005-b8ea-7328119aec97
< 3.7.31
MEDIUM 4.3 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthor… wordfence
ff5d0ffb-c703-4bd1-83a0-c02e3744dd03
< 5.2
MEDIUM 4.3 The Taxonomy/Term and Role based Discounts for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forg… wordfence
ff4b757a-9ede-496b-b559-cf952d39fe70
< 2.5.7
MEDIUM 4.3 The GamiPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.6. … wordfence
ff4895bb-b353-423c-a135-bf504ad77e53
< 3.8.4.5
MEDIUM 4.3 The AI WP Writer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.… wordfence
← Prev 1342 1343 1344 1345 1346 1347 1348 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top