πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1347 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fdea1999-a282-4374-a093-5cbd5b05497a
< 1.7.8
MEDIUM 4.3 The WordPress Flipbook by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
fde1157b-5b99-4e9c-9c51-ebaa0eddfd73
< 1.3.1
MEDIUM 4.3 The CM On Demand Search And Replace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
fdd57b3b-bd0a-4b07-831e-72f2329b2577
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
fdd20b94-3677-4eca-9c59-4a3c61d493da
< 2.5.3
MEDIUM 4.3 The Auto Alt Text plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
fdaf3f4e-18fd-41d5-ad9c-7e6141f90c52
< 2.3.5
MEDIUM 4.3 The WP Inventory Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
fd853c75-dd36-4073-af9e-446b2506c758
< 1.0.7
MEDIUM 4.3 The WP Page Loading plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
fd7da039-f6b8-46b7-a43a-145e9f8844c3
< 3.2.13
MEDIUM 4.3 The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
fd7a1440-18f5-4bcb-a4cf-c4713375d0a1 MEDIUM 4.3 The Shockingly Simple Favicon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
fd741e2d-5478-4b9a-83ab-7ccafdc5d12f
< 1.3.4
MEDIUM 4.3 The Ruby Help Desk plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorizatio… wordfence
fd68a27f-e4d1-4f8e-ba35-e8dfa7756856 MEDIUM 4.3 The WP DB Booster plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
fd5638b6-134d-4386-af40-6ac961a915d7
< 2.2.17
MEDIUM 4.3 The School Management System – WPSchoolPress plugin for WordPress is vulnerable to arbitrary user deletion due to a mi… wordfence
fd2fed79-3ed2-4a05-b0b1-e902f53a1933 MEDIUM 4.3 The Forget About Shortcode Buttons plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
fd25b485-1355-4654-a75f-ec2334ba34de
< 2.5.0
MEDIUM 4.3 The PostmarkApp Email Integrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
fd03684a-3c97-4364-bcb9-a1938edf9ce3
< 1.1.10
MEDIUM 4.3 The Hydra Booking β€” Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized acces… wordfence
fd00c5cc-1a28-4d94-815d-46219ce0e0e9 MEDIUM 4.3 The Custom My Account for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
fcfe2625-3ee8-4822-8088-abf0b898bebb
< 2.8.150
MEDIUM 4.3 The GeoDirectory plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.… wordfence
fceae728-ea72-4586-848f-3a45b6f9699a
< 3.4.1
MEDIUM 4.3 WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows r… wordfence
fcddcf58-7fb7-4fe9-8353-5ec62c5c16d1 MEDIUM 4.3 The SEO For Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
fcc35b14-ace8-4f2d-8025-f837f1da1687 MEDIUM 4.3 The Bulk Watermark plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
fcbbae9e-2efc-4d7e-8daf-3f389b501091 MEDIUM 4.3 The AIO WP Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
fc9e6374-8f9e-4c60-a86b-46cd4122abf9 MEDIUM 4.3 The The Bucketlister plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
fc7e68e7-6792-419d-800b-f1bc340f23fb
< 1.7.19
MEDIUM 4.3 The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
fc707604-b2ce-4925-b3aa-eeb850543ca1
< 0.7.4
MEDIUM 4.3 The Petitioner plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
fc626bdb-e962-407c-95c3-3f9e28dc5876 MEDIUM 4.3 The BC Menu Bar Cart Icon For WooCommerce By Binary Carpenter plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
fc5a8506-b191-4ab3-9c59-4f1150be6a38
< 3.7
MEDIUM 4.3 The Checkfront Online Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
← Prev 1344 1345 1346 1347 1348 1349 1350 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top