๐Ÿ›ก๏ธ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1346 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ff2a24ad-6a58-4b01-91e6-de6ba7856fcf
< 1.2.9
MEDIUM 4.3 The DarkMySite โ€“ Advanced Dark Mode Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forg… wordfence
ff28f33f-85d1-4987-975b-ee3bbcb394f4
< 4.0
MEDIUM 4.3 The Vuukle Comments, Reactions, Share Bar, Revenue plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
ff2097a9-fe7a-48f3-be9c-dc0caef74262
< 1.2.3
MEDIUM 4.3 The WooCommerce Box Office plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
ff153e64-638d-4883-aa25-e0c20977cca0 MEDIUM 4.3 The WordPress Infinite Scroll by Auto Load Next Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
fefe4499-8b03-4c07-b248-ae0ae5153b4f
< 7.6
MEDIUM 4.3 The Link Library plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.5.… wordfence
fee47bb5-5af9-426c-8760-193276e046ea
< 3.2.7
MEDIUM 4.3 Multiple plugins and/or themes by Inisev for WordPress are vulnerable to unauthorized access due to a missing capability… wordfence
fee05dce-f484-422a-88cc-9923af1fee43
< 1.27.9
MEDIUM 4.3 The Post and Page Builder by BoldGrid โ€“ Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Travers… wordfence
fedf20b2-6c21-4c91-8f79-9cac334a1313 MEDIUM 4.3 The Auto Limit Posts Reloaded plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
febca991-90a0-46b8-9609-2c8a71b5eb5f
< 2.8.6
MEDIUM 4.3 The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin… wordfence
feb4f3dc-9abf-4ee3-834e-e5516652d810 MEDIUM 4.3 The Google XML Sitemap for Videos plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
feb13137-4708-43da-9a5a-b7af8356942d
< 6.0.0
MEDIUM 4.3 The Analytify โ€“ Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable … wordfence
feb0f29c-78df-46e6-a6f4-c8548d3e5185 MEDIUM 4.3 The Full Screen Menu for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and… wordfence
fea1a37a-1c28-4a7c-a0f1-54c1d1b52ce3 MEDIUM 4.3 The JSP Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
fe996511-f29a-4e28-b6de-3633d45b10c1
< 1.3.3
MEDIUM 4.3 Cross-site request forgery (CSRF) vulnerability in the Calendar plugin before 1.3.3 for WordPress allows remote attacker… wordfence
fe9659ff-7233-44d4-aaff-ad3089511a67
< 1.11.3
MEDIUM 4.3 The WP Migration Plugin DB & Files โ€“ WP Synchro plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… wordfence
fe951dc0-7b29-4cad-a86b-6b1f6bcca18b
< 2.2.9
MEDIUM 4.3 The Product Feed for WooCommerce โ€“ Google Shopping Feed, Pinterest Feed, TikTok Ads & More plugin for WordPress is vul… wordfence
fe8457ee-c408-40f9-aca4-97e76efa2847
< 8.2
MEDIUM 4.3 The SEOPress โ€“ On-site SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
fe7f75b4-f315-44f7-8e67-1680eeee3942
< 1.5.9
MEDIUM 4.3 The Responsive Vertical Icon Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
fe43d128-46ac-42e2-9469-02772dc1ad52 MEDIUM 4.3 The Specia Companion plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
fe41d8a7-c1d9-4c1a-9330-50baa3fa449d
< 1.1.2
MEDIUM 4.3 The Bookify โ€“ Appointment Booking & Scheduling for WordPress plugin for WordPress is vulnerable to unauthorized access… wordfence
fe3834a6-a6f5-4cc7-951e-a6ada6346b07
< 4.15.4
MEDIUM 4.3 The MStore API โ€“ Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file up… wordfence
fe2fd740-b5b5-4a2a-88fc-b19b2f0f6a2b
< 6.12.0
MEDIUM 4.3 The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on t… wordfence
fe29d7bf-3cf8-429c-91d7-2a8038749c42
< 2.11.25
MEDIUM 4.3 The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
fe238a78-7eaa-487f-a7bd-50a96432d395 MEDIUM 4.3 The WordPres ๅŒๆญฅๅพฎๅš plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
fdfac5bc-89ac-4ed7-85e9-a4a1ff0bfbff
< 5.0.11
MEDIUM 4.3 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution โ€“ Build Your Own Amazon, eBay, Etsy plugin for Word… wordfence
← Prev 1343 1344 1345 1346 1347 1348 1349 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top