πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1357 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f31b42c8-cf82-49cf-ac4c-d42a28252d66
< 1.2.3.1
MEDIUM 4.3 The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make su… wordfence
f31a42c1-afb7-4a44-b4e8-f68c622bc43e
< 4.4
MEDIUM 4.3 The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
f3108ef4-f889-4ae1-b86f-cedf46dcea19
< 1.7.2
MEDIUM 4.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a mi… wordfence
f30ae90a-54fb-4c55-a6ed-9c411a6997fb
< 1.12.2
MEDIUM 4.3 The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information D… wordfence
f3063e92-e152-440d-bf02-b852ff87e319
< 3.1.1.2
MEDIUM 4.3 The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to accoutn takeover in all ver… wordfence
f3045ebf-70af-4124-9116-42c07f64a3bf
< 2.6.7
MEDIUM 4.3 The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is … wordfence
f2fc0457-ee9b-4571-b1ef-0649dde1badb MEDIUM 4.3 The Easy Hotel Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
f2fb18eb-a5ce-463f-aae2-55dc0bb3e9c7
< 5.4.3
MEDIUM 4.3 The Classified Listing – AI-Powered Classified ads & Business Directory plugin for WordPress is vulnerable to unauthor… wordfence
f2eccedd-c75e-41d8-b2de-9977b1143cc2
< 4.6.1
MEDIUM 4.3 The JSM Show Post Metadata plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
f2cdd50d-6290-4cef-a72c-2e9d680d4f1f
< 3.3.33
MEDIUM 4.3 The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions … wordfence
f2b31db1-c4f7-47c6-ad83-7ecd375e5f65 MEDIUM 4.3 The Piotnet Addons For Elementor Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
f2b1e9a7-cbbd-4915-a1bb-e98bb70aa6a1 MEDIUM 4.3 The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … wordfence
f2a79874-6dfe-41e7-a29b-2ee6b3753264
< 4.0.7
MEDIUM 4.3 The Adminify plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
f29c44b4-903c-4165-9c2d-ede4e0086e85 MEDIUM 4.3 The Pre-Publish Post Checklist plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
f29843c7-6249-4f6f-8238-f3b0d94ec10a
< 2.15
MEDIUM 4.3 The Merge + Minify + Refresh plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
f29514d0-20a5-43f2-bf36-660579103220
< 6.2.1
MEDIUM 4.3 The Dollie Hub – Build Your Own WordPress Cloud Platform plugin for WordPress is vulnerable to Information Exposure in… wordfence
f2949ff1-5c69-4189-99a9-e50c65c78461
< 2.1.4
MEDIUM 4.3 The Freesoul Deactivate Plugins – Plugin manager and cleanup plugin for WordPress is vulnerable to Cross-Site Request … wordfence
f26a6ace-4623-4931-a4e4-8176d799d274
< 1.3.7
MEDIUM 4.3 The WordPress Hosting Benchmark tool plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
f25de9b7-cd9d-4211-9201-816645b2caf9 MEDIUM 4.3 The WP Subscription Forms PRO plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
f256036d-11e8-4311-baa0-d15193c72da0
< 3.3.53
MEDIUM 4.3 The Eventin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_fi… wordfence
f250793b-40c3-4362-bc0c-e3d65c922288
< 2.2.1
MEDIUM 4.3 The WP Logger plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
f24cfefe-f671-456d-a378-44a41fc81c0e
< 2.0.4
MEDIUM 4.3 Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPr… wordfence
f23b144e-4380-4099-89b5-816c8c2f710f
< 5.0.12
MEDIUM 4.3 The WP Attachments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
f2358979-25b9-4c52-88dc-25390be6bd22
< 5.10.3.1
MEDIUM 4.3 The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t… wordfence
f231da1f-7eea-4fba-96b8-1f6e0c6ee3c2 MEDIUM 4.3 The Custom Style plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… wordfence
← Prev 1354 1355 1356 1357 1358 1359 1360 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top