πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1355 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f5779c73-0188-4b8c-9f1d-7d00d234a334
< 8.5.5
MEDIUM 4.3 The WP eStore plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.5… wordfence
f5740c07-28b3-40ce-997e-e4ec76348cf4 MEDIUM 4.3 The Feed Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… wordfence
f570a9d2-41d7-42f2-9f13-4cda97ea2219
< 4.1133
MEDIUM 4.3 The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to unauthorized ac… wordfence
f56a1306-d1e2-4731-81a7-9c95ff26ca71
< 1.2.7
MEDIUM 4.3 The WP Gravity Forms Keap/Infusionsoft plugin for WordPress is vulnerable to Open Redirect in all versions up to, and in… wordfence
f55af49e-82c8-462b-8c0b-a25e966a27af
< 6.4.5
MEDIUM 4.3 The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
f557ddf1-cee3-498c-87bc-fa81bf574591
< 2.7
MEDIUM 4.3 The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
f54f1e41-788b-45e5-b84f-06e664f5c597
< 1.14.4
MEDIUM 4.3 The Email Marketing for WooCommerce by Omnisend plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers… wordfence
f543b7b2-4cc9-4152-8885-a166b969a937
< 1.0.36
MEDIUM 4.3 The Teluro theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.31. Thi… wordfence
f5419189-692f-4966-9baf-016188cf133c
< 1.4.2
MEDIUM 4.3 The Copyscape Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
f53e9354-248f-4d13-a1c0-8355b268fae2
< 1.2.0
MEDIUM 4.3 The WP News plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. Th… wordfence
f52c9317-9345-452a-915c-e9add31af783
< 5.10.5.1
MEDIUM 4.3 The TheGem (Elementor) theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
f51f0919-498e-4f86-a933-1b7f2c4a10a4
< 4.5.2
MEDIUM 4.3 The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the … wordfence
f515ccf8-7231-4728-b155-c47049087d42
< 3.10.8
MEDIUM 4.3 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… wordfence
f5030dd8-b723-443f-9dff-1f4d4c37b4fb
< 2.2.8
MEDIUM 4.3 The Endless Posts Navigation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
f4fe3ad9-247f-4e5d-8c79-0970afaa7729
< 2.4.30
MEDIUM 4.3 The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnera… wordfence
f4fe0a29-aa0c-423d-874f-7a0242fef996
< 6.4.4
MEDIUM 4.3 The Photo Engine (Media Organizer & Lightroom) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… wordfence
f4fa85b4-df6e-4b7d-9b8b-940c5f102556
< 1.2.8
MEDIUM 4.3 The Automatic Featured Images from Videos plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
f4f84b2a-2674-42a1-9db1-d9c1f3db2376
< 2.1.6
MEDIUM 4.3 The Woocommerce Blocker Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
f4ef2ced-3c82-4379-8b14-1cf11482fd35
< 7.7.0
MEDIUM 4.3 The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable t… wordfence
f4e2f6a8-0576-4a43-9061-9878b7d59399 MEDIUM 4.3 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
f4cd5a8c-d114-4b88-aaf1-aa525cd33595 MEDIUM 4.3 The RPS Include Content plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
f4afcb16-9c97-483f-be48-31b5156bcca3
< 7.1.2
MEDIUM 4.3 The Booster Elite for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
f4aac424-abf3-4d6c-a0a4-a95e2cf89864
< 7.3
MEDIUM 4.3 The Visitors Traffic Real Time Statistics plugin for WordPress is vulnerable to unauthorized access of data due to a mis… wordfence
f4a38e5d-758b-490e-9ada-c58646c4e8c9
< 5.0.3
MEDIUM 4.3 The SiteLock Security plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
f490dd2b-34d6-4e19-8788-d30ad0c67e95
< 11.8.1
MEDIUM 4.3 The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to Insecure … wordfence
← Prev 1352 1353 1354 1355 1356 1357 1358 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top