πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1349 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fb0ceb76-08ae-40c6-ad28-d013d40dc223 MEDIUM 4.3 The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver… wordfence
fb0b00cb-6c14-4ef5-a5a9-34f66abfa166
< 2.13.4
MEDIUM 4.3 The Zoho Flow – Integrate 100+ plugins with 1000+ business apps, no-code workflow automation plugin for WordPress is v… wordfence
fafcea5a-1f84-4342-8959-312e3938e4d3
< 2.0.4
MEDIUM 4.3 The QR Redirector plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
faf5c00e-e92a-4c1f-9081-20cf36ecabbc
< 3.2.4
MEDIUM 4.3 The Booking calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
faf44730-b975-4057-96dc-7284775500f9
< 3.1.1
MEDIUM 4.3 The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulne… wordfence
fadd7934-bdd9-47e9-bd34-d162ff3b7cd4 MEDIUM 4.3 The LH Signing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.… wordfence
faad339f-96d6-4937-a1f3-9d2d19bc6395 MEDIUM 4.3 The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… wordfence
fa9a8227-6e2a-4375-9672-20290ece292c
< 3.9.13
MEDIUM 4.3 The Tutor LMS plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin… wordfence
fa87a84c-1ab2-4bc8-8af3-02836b680066
< 1.5.5
MEDIUM 4.3 The Hash Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
fa85821b-5769-4ff4-ac92-f558aec86f78 MEDIUM 4.3 The JobBoard Job listing plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions u… wordfence
fa7430ca-b102-46c0-869a-05fb004a276f MEDIUM 4.3 The RAYS Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3… wordfence
fa73c2a0-a692-47db-99ca-7e7159fc96aa
< 1.2.1
MEDIUM 4.3 The Swatchly – WooCommerce Variation Swatches for Products plugin for WordPress is vulnerable to Cross-Site Request Fo… wordfence
fa6fc22e-0d30-4c4b-8c8d-13f04ed1aa7c
< 1.3.3
MEDIUM 4.3 The ARI Stream Quiz – WordPress Quizzes Builder plugin for WordPress is vulnerable to content injection due to imprope… wordfence
fa62c795-57b8-48e5-a49f-2e1f3c792c87
< 3.7.6
MEDIUM 4.3 The Kadence Blocks β€” Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Informa… wordfence
fa5b1bf3-344e-4ae6-87b9-2dcaafd417a5
< 5.1.7
MEDIUM 4.3 The Essential Real Estate plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability … wordfence
fa530112-a7cd-4c54-aa87-9e7337d01557
< 1.3.60
MEDIUM 4.3 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_… wordfence
fa41534d-3285-4002-8cca-a390586dface
< 2.1.1
MEDIUM 4.3 The Himer theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. T… wordfence
fa32f55a-f9e4-4129-add0-39d9e4eb1bee
< 3.6.23
MEDIUM 4.3 The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to Cross-Site Req… wordfence
fa2b0487-72a7-4e49-a25b-d910e9880246 MEDIUM 4.3 The Everest Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
fa22a038-3a7e-4821-952f-c163299ddee0
< 1.0.4
MEDIUM 4.3 The WP Tweet Walls plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
fa2258e4-f802-490b-8c10-4f008698a032
< 8.6.0
MEDIUM 4.3 The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.5.2… wordfence
fa1e0bcd-f881-4b01-b802-7cb18a22a07f
< 6.2.0
MEDIUM 4.3 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization by… wordfence
fa1d2fac-6e66-46b8-aa0a-1f6b5746b18b
< 3.4.1
MEDIUM 4.3 The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized access of data due to a mi… wordfence
fa17f78a-5e4a-441e-bbbb-d13bad648c39
< 1.5.5
MEDIUM 4.3 The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via… wordfence
fa0b8026-5c7b-4a4a-93a7-3931da3e3967
< 2.6.4
MEDIUM 4.3 The Grand Conference Theme Custom Post Type plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
← Prev 1346 1347 1348 1349 1350 1351 1352 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top