πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1353 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f72ba0e2-a9c4-43b0-a01f-185554090162
< 6.1.0
MEDIUM 4.3 The WooCommerce CVR Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… wordfence
f72820ec-5638-4c65-a0bd-355b8ca2435c MEDIUM 4.3 The Page Manager for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t… wordfence
f713f2f8-545a-4f54-a028-8422c0942a63
< 2.1.6
MEDIUM 4.3 The Wholesale Suite plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability che… wordfence
f711c9d0-aa56-4e4c-bbcf-afa9598c3518
< 2.27.22
MEDIUM 4.3 The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
f709fca2-b7b6-4567-8055-1156f510d1ca
< 1.8.4
MEDIUM 4.3 The Envo Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.3.… wordfence
f6f91816-a263-4938-bac1-eeb3bb2fc120 MEDIUM 4.3 The Novo-Map : your WP posts on custom google maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
f6f12812-3c14-41c1-b14b-af84f835a773 MEDIUM 4.3 The AP Background plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
f6ef2976-0fae-4b8f-b63a-7de7390cbd00
< 3.0.9
MEDIUM 4.3 The Quiz Cat – WordPress Quiz Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
f6d90ca3-dc24-4634-9f98-83a909e3e093 MEDIUM 4.3 The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
f6d44749-8b1a-4d22-9917-fee134737063 MEDIUM 4.3 The Just Custom Fields plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… wordfence
f6cf31f0-b560-40c5-b6e4-4fc444e6d23b MEDIUM 4.3 The Super Static Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
f6ca7fc4-a5fb-4f8a-b49e-413956b8ac96 MEDIUM 4.3 The Institutions Directory plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
f6c8bd7c-0d9e-444d-9e0f-ccdd84b9b6dd
< 1.0.6
MEDIUM 4.3 The Writesonic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
f6c5e3f8-ebbd-4cc3-b9b1-3f1704e3c07a
< 2.12.9
MEDIUM 4.3 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulner… wordfence
f6bdd745-066d-4b8e-a66c-6d3fb9a9ef12
< 9.1.4
MEDIUM 4.3 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
f6b9e63f-0492-4d51-a8ae-0874ef57e852
< 8.2.7
MEDIUM 4.3 The WordPress Tooltips plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
f6b87ed9-84c9-497e-a8dc-96dfa9b940b7 MEDIUM 4.3 The Grand Magazine theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5… wordfence
f6a0d6df-60a6-42e3-9e9b-6171bb589f4e
< 2.9.0
MEDIUM 4.3 The CM Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.9.0. This i… wordfence
f69dfe83-03cb-47e1-b462-7ba4998e9cd3 MEDIUM 4.3 The Actionwear products sync plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
f6914ae1-6e31-4a5b-8dac-4d2ee96a6bd9 MEDIUM 4.3 The Attractive Donations System - Easy Stripe & Paypal donations plugin for WordPress is vulnerable to Cross-Site Reques… wordfence
f68e6fed-1986-4172-8270-0460450d6a02
< 3.8.7
MEDIUM 4.3 The Newspack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
f6893498-5cd0-4649-893c-a204508cfd04
< 5.1.7
MEDIUM 4.3 The No External Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
f670b93e-da2e-43e7-a28a-6cacba4df3a1
< 2.51
MEDIUM 4.3 The Simple Author Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
f6658edb-11dc-4594-8936-95d60d581f49
< 6.24.2
MEDIUM 4.3 The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers… wordfence
f65ee908-004f-4526-aeca-41b36522bb30
< 4.0
MEDIUM 4.3 The GoHero Store Customizer for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due … wordfence
← Prev 1350 1351 1352 1353 1354 1355 1356 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top