πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1351 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f9173644-f0b2-4de3-8e58-fd556d8e38cd MEDIUM 4.3 The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
f8f663f6-b778-484b-8998-cfd9ffb743be
< 5.12.8.1
MEDIUM 4.3 The WP Booking System – Booking Calendar Premium plugin for WordPress is vulnerable to unauthorized access due to a mi… wordfence
f8f372cb-739f-44e2-9074-e91b8c903837
< 23.3
MEDIUM 4.3 The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
f8deef7d-d755-489d-847a-64eecb13f7a6
< 10.0.10
MEDIUM 4.3 The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Sensitive Inform… wordfence
f8cba9d2-e973-48e9-b69d-3f8b6c4833d5
< 3.6.0
MEDIUM 4.3 The DoFollow Case by Case plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
f8bf0933-1c97-4374-b323-c55b91fe4d27
< 4.0.7
MEDIUM 4.3 The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability… wordfence
f89aeafd-3449-46b0-b350-bb3b7b08a47d
< 10.30.4
MEDIUM 4.3 The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
f8991817-b280-474e-9120-550bacb07066
< 1.5.2
MEDIUM 4.3 The Hide Shipping Method For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
f8906333-7024-40d3-91cd-2ecbbf20314f
< 1.6.18
MEDIUM 4.3 The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Fo… wordfence
f88c00ca-cf9e-44e7-9495-686ace1ead21 MEDIUM 4.3 The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu… wordfence
f88b8f3f-b4e0-482e-a2e8-dc0f3529a37e
< 5.1.1
MEDIUM 4.3 The Matomo Analytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
f8722424-44a1-4dee-819e-039df762a3dc
< 1.1.1
MEDIUM 4.3 The Simple Folio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
f870f201-deed-4ee1-8468-35cf469b6e6d MEDIUM 4.3 The XM-Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9… wordfence
f86e8ccb-a865-4da5-9250-dd715b8cdbe7
< 1.9.3
MEDIUM 4.3 The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
f862afea-cd35-4aa4-aba6-df12a3728776
< 2.5.6
MEDIUM 4.3 The JobSearch plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
f853415c-ea8d-4330-b4e3-fc0c7c6bcbd1
< 0.2.4
MEDIUM 4.3 The Kargo Takip plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
f83be46f-3b51-4a30-88a4-388bcbfd0d2a MEDIUM 4.3 The SB Child List plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5… wordfence
f8390dc5-24db-4d39-ba26-eaa87d260f1c
< 1.2.8
MEDIUM 4.3 The Youzify plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
f822d5b9-46fb-4910-8d92-8c73e01d7e50
< 2.38.0
MEDIUM 4.3 The YITH WooCommerce Compare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
f8225e3c-5413-4406-a31b-80829b6b330a MEDIUM 4.3 The Apptivo Business Site CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
f81f4bae-22b1-42e1-a275-2b302b68912e
< 4.0.25
MEDIUM 4.3 The WordPress Event Manager, Event Calendar and Booking Plugin plugin for WordPress is vulnerable to unauthorized access… wordfence
f8152adf-1ca9-4a19-b539-39e257ab94c8
< 1.6.28
MEDIUM 4.3 The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized delet… wordfence
f814debc-8e5c-4329-ba08-d82b0b97a1b8 MEDIUM 4.3 The Stock Message plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1… wordfence
f813cb1a-5922-48a5-a026-66ec9aaac294
< 4.8.7
MEDIUM 4.3 The Slider Pro plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check… wordfence
f8109e13-c7c7-4789-9630-efd31e27986b MEDIUM 4.3 The JPG, PNG Compression and Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
← Prev 1348 1349 1350 1351 1352 1353 1354 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top