ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1356 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f47d53e1-42ac-425e-a6f2-901a6d26845d
< 4.9.3
MEDIUM 4.3 The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable t… wordfence
f478db7f-6339-446e-b00d-0710707e679a MEDIUM 4.3 The Custom Login And Signup Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
f458663f-6b1a-4acd-b2db-c66d7a915ab7
< 1.10.20
MEDIUM 4.3 The Popup by Supsystic plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i… wordfence
f455f3a8-7def-49de-b006-51f4a51aa40b
< 2.16.2
MEDIUM 4.3 The ЮKassa Ð´Ð»Ñ WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
f43bef8a-0df5-43f8-a87d-5f482b14a3c6
< 1.1.6
MEDIUM 4.3 The Tasty Recipes Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
f42c6462-9206-460c-94c0-859306886c88 MEDIUM 4.3 The Salvador – AI Image Generator plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
f428b90d-8830-445d-b1f1-d8f860dae5cf MEDIUM 4.3 The Login Page Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
f412025b-42c3-4a65-a49b-d6dee4b73eff MEDIUM 4.3 The Silverlight Video Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
f407140c-e0ad-476e-a04d-ff084c88bdb1
< 2.8.2
MEDIUM 4.3 The Wired Impact Volunteer Management plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
f3ff473c-c629-487c-9b18-e074534c7b79
< 3.7.35
MEDIUM 4.3 WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam … wordfence
f3fae909-5564-4e0a-9114-edd0e45865e5
< 3.1.14
MEDIUM 4.3 The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to … wordfence
f3eec9c6-fef9-4d6e-8328-51efb997c99c
< 8.8.4
MEDIUM 4.3 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through u… wordfence
f3e2ddde-1421-4352-b93a-1492574f624e
< 4.3.0
MEDIUM 4.3 The CM Tooltip Glossary – Powerful Glossary Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
f3e1851a-9545-4687-b58b-5cdad3291525
< 1.4.3
MEDIUM 4.3 The Email Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
f38543ff-1074-4273-be33-8142d59e904f
< 3.5.6
MEDIUM 4.3 The Duplicate Post, Page and Any Custom Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all… wordfence
f3845071-8419-4bb2-b22d-f9ae22fb7d6a
< 3.1.6
MEDIUM 4.3 The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is v… wordfence
f37cc9d0-345e-4ab7-ae99-d9d7fee6c1e5
< 3.1
MEDIUM 4.3 The Product Enquiry for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
f37c4b2c-6f41-46b5-8427-b1883b39322e
< 3.0.7
MEDIUM 4.3 The JetFormBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.… wordfence
f374a57f-e4a4-4771-a887-86b3e8a8acca MEDIUM 4.3 The Industrial Lite theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
f36b3571-1dc1-4c2f-8888-5fd823ce1954
< 5.2.2
MEDIUM 4.3 The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom… wordfence
f36b0c89-3bce-40c3-b28d-8bd3d132bc5d MEDIUM 4.3 The LWS Affiliation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
f35c4e21-a6d6-4821-a415-2ff40ea76f99 MEDIUM 4.3 The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could a… wordfence
f355d2c0-6133-4091-b900-1451ebba70c4 MEDIUM 4.3 The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to unauthorized modification of da… wordfence
f347a629-523e-4ec4-ad56-6ae9357dd7f5
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
f3344e72-1dd6-45ec-b699-d755589a1566 MEDIUM 4.3 The Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters plugin for WordPres… wordfence
← Prev 1353 1354 1355 1356 1357 1358 1359 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top