πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1354 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f6461a8f-297e-49ad-aa9b-9379f0984423 MEDIUM 4.3 The WP-CopyProtect [Protect your blog posts] plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
f6409626-c8cb-412c-aff3-cbb2da212e5d
< 3.1.3
MEDIUM 4.3 The MailMunch – Grow your Email List plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
f5fba145-5cb6-4ea1-8691-6bad3dcfbcf4
< 6.4.1
MEDIUM 4.3 The ARforms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
f5f89ca2-caf3-4dc1-b1cb-0b0bef23a185 MEDIUM 4.3 The Google SEO Pressor for Rich snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
f5e90403-434f-46d3-bdac-c7ad013f71b4
< 2.4.5
MEDIUM 4.3 The Cue by AudioTheme.com plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
f5e66037-0cce-4881-adec-1b1ff0c3747b
< 1.0.1
MEDIUM 4.3 The Offload Videos – Bunny.net, AWS S3 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
f5dead05-5960-4ccb-89c2-c8bb0cd9c9e9 MEDIUM 4.3 The Change WP URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
f5da3a4f-7084-4ba9-89c9-5a480efc7eca MEDIUM 4.3 The CSprite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This… wordfence
f5d5c1b8-112a-465f-801e-17c382e3d357 MEDIUM 4.3 The Suggestion Toolkit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
f5cb0b5d-062c-47ac-bcd0-f30f82da6491
< 8.2.5
MEDIUM 4.3 The WP Customer Area plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
f5c122a5-20d0-450f-aec6-fc7cfc9cc6dc
< 9.5.10
MEDIUM 4.3 The Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) plugin for WordPress is vulne… wordfence
f5ba8c79-1093-43aa-8273-2dbbe3172fec
< 2.4.1
MEDIUM 4.3 The IP Based Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
f5b18726-a880-4e06-8f33-77aea7323000 MEDIUM 4.3 The Xola plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in al… wordfence
f5b08a10-f6bc-44a0-865a-5ad71a1772f7
< 2.6.9
MEDIUM 4.3 The Ultimate Member plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
f5a87c5c-9871-464f-850e-64141cc050ef
< 1.7.4
MEDIUM 4.3 The WP Fundraising Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
f5a7aa18-b6a9-4cd1-a502-25c0888ac227
< 2.8.6
MEDIUM 4.3 The ShopLentor Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
f5a5ba98-5fe2-48d6-b1fa-22cb6da1cbed MEDIUM 4.3 The Fitness FSE theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
f59f2983-722d-4243-9a0c-e0f72c22e4fe
< 2.2
MEDIUM 4.3 The LifePress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
f59d9d8a-467a-4920-963a-da45f1f4462f
< 2.2.4
MEDIUM 4.3 The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc… wordfence
f59cf3d6-06a0-42ec-a604-5f59c6b2be40
< 4.5.7
MEDIUM 4.3 The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification due to a missing capability… wordfence
f5944f62-845b-40a9-af2f-c7ee815e811d
< 1.4.6
MEDIUM 4.3 The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulner… wordfence
f58f994e-0a9b-4b40-9e38-535169c793d3
< 4.1.6
MEDIUM 4.3 The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a … wordfence
f58efd6c-58f2-464b-8aaf-f4f5c4c52f09
< 5.7.2
MEDIUM 4.3 The ProfileGrid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.7.… wordfence
f57d99dc-3faa-4dfc-9cb6-fdb5647daf9a
< 5.21.0
MEDIUM 4.3 The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to… wordfence
f57b8ed5-f7cf-451b-b6ee-346b6c92d60b
< 3.3.1
MEDIUM 4.3 The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to unau… wordfence
← Prev 1351 1352 1353 1354 1355 1356 1357 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top