πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1352 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f80a1f13-c1b9-4259-8d96-71a3cbcaf4ca
< 1.5.8
MEDIUM 4.3 The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
f8068fb3-5a19-4b17-848b-32cebfff2537
< 26.6.3
MEDIUM 4.3 The Betheme theme for WordPress is vulnerable to authorization bypass in versions up to, and including, 26.6.2. This is … wordfence
f7f9b1ef-2efc-4d88-bff8-e0dd711b85ab
< 1.7.1002
MEDIUM 4.3 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
f7f77ca2-c69e-4f59-ad7b-a244863de424
< 3.2.8
MEDIUM 4.3 The WP2LEADS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several func… wordfence
f7ed8472-1e42-4abd-9978-8f5080ec2ee1
< 1.2.1
MEDIUM 4.3 The OwnerRez plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.… wordfence
f7ed53bd-08de-4ec9-a8dd-eef72b788359
< 2.16.0
MEDIUM 4.3 The OptinMonster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
f7ce1d19-25fa-434d-943b-d10c5cb2ec51
< 6.0.4
MEDIUM 4.3 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… wordfence
f7cd392e-f223-4c39-bdf7-f0584c5b5bd8 MEDIUM 4.3 The Publitio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, … wordfence
f7be0fe9-3b6a-47e7-8a18-856b0e164f09
< 1.3.0
MEDIUM 4.3 The Business One Page theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
f7b45b1d-7ed6-4382-b69c-45ea45e4d0db
< 3.9.12
MEDIUM 4.3 The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in for… wordfence
f7b239b1-c234-40d0-a4bc-f2db54937494
< 8.2.0
MEDIUM 4.3 The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable … wordfence
f7afbe2b-72a8-40da-bc94-ff2a1b9569b4
< 3.8.2.3
MEDIUM 4.3 The Brands for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including,… wordfence
f7afae24-a905-473f-8015-c93b60189eb5 MEDIUM 4.3 The Testimonial Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
f7a2c607-a18b-49b5-ac72-892c570a5b8d
< 11.0.0
MEDIUM 4.3 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is… wordfence
f79f9385-f8d1-44a0-9e53-7576a9453163
< 1.8.4
MEDIUM 4.3 The Customize My Account for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
f79d3938-bf85-4e0d-80a3-2ff365482d36
< 37
MEDIUM 4.3 The DH – Anti AdBlocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
f785edc7-b5c1-4c39-bc66-d9d1404a2048
< 8.5.6
MEDIUM 4.3 The WP eStore plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.5… wordfence
f779443a-e5b9-45d6-bfd3-d22243d34917
< 1.6.6
MEDIUM 4.3 The Simple calendar for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
f7663085-970e-4d11-b63e-8363a51e3acd
< 1.3
MEDIUM 4.3 The Product Quantity Dropdown For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… wordfence
f765e21e-938a-4110-8fdf-12315e2a79cc
< 1.8.3
MEDIUM 4.3 The Futurio Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8… wordfence
f76411f1-98ea-4d75-9ddd-e41a5d08c698
< 1.1.1
MEDIUM 4.3 The SRS Simple Hits Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
f75c3ed0-3b05-4132-b102-ba64fb8c338d
< 5.4.5
MEDIUM 4.3 The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
f7551d48-0858-4d82-aaca-3b04741938fd MEDIUM 4.3 The Portfolio Gallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
f7474e9c-8db2-44ac-80d6-c8b105786af6
< 1.2.0
MEDIUM 4.3 The SureDash plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, … wordfence
f738ecf3-5f10-43ab-b8ce-34ac41229e9b
< 6.3.0.1
MEDIUM 4.3 The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
← Prev 1349 1350 1351 1352 1353 1354 1355 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top