πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1358 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f22bb2ec-9d8d-45f6-9a86-cb5099fa301c
< 1.13.4
MEDIUM 4.3 The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… wordfence
f2262c0f-6839-43aa-9e19-9ccee6341ad7 MEDIUM 4.3 The Simple Giveaways – Grow your business, email lists and traffic with contests plugin for WordPress is vulnerable to… wordfence
f21c9730-0834-4126-bc0d-c5f84b46dce9
< 6.8.1
MEDIUM 4.3 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
f212550c-1c93-4c3b-9eb2-b61cbe1eebb1 MEDIUM 4.3 The Simple Price Calculator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
f20d9160-bddf-4fdb-a5a6-cc792bb1c1ee
< 5.1.2
MEDIUM 4.3 The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
f1f69f93-80e3-434d-98a6-fc8757b4e6d1
< 3.15.2
MEDIUM 4.3 The Avada (Fusion) Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… wordfence
f1f06f3d-ca03-470a-b63c-9ad7426472b7 MEDIUM 4.3 The Authors List plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
f1eb9ec6-897a-4c38-a85c-033d7050dcfa
< 6.12.28
MEDIUM 4.3 The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … wordfence
f1e50d8c-e61c-4e94-b5e8-b24832dc24b6
< 5.0.13
MEDIUM 4.3 The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
f1d3b954-2a3f-4be9-ad0a-dfc0774d8d91
< 2.9.1
MEDIUM 4.3 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
f1bd7a28-cc48-4d99-8c4c-84cb810193ca
< 1.5.3
MEDIUM 4.3 The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to Cross-… wordfence
f1b6f041-5ea6-48ca-9ca7-4ce96cbfa275
< 1.10.0
MEDIUM 4.3 The WP Migration Plugin DB & Files – WP Synchro plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… wordfence
f1aa6c8b-8231-49f1-a30a-fc1a03813221
< 3.0.0
MEDIUM 4.3 The ProductX – Gutenberg WooCommerce Blocks plugin for WordPress is vulnerable to unauthorized modification of data du… wordfence
f1a2a09d-b50e-499d-8cfd-6e2884e66127
< 2.4.0
MEDIUM 4.3 The EazyDocs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… wordfence
f19a9bbb-9c7b-490f-b016-2e72ab2b35a5 MEDIUM 4.3 The KiotViet Sync plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
f1946a48-c1d6-4ca9-909f-0d4b78c25c36 MEDIUM 4.3 The delete-post-revisions-on-single-click theme for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
f18c1d00-ed8a-4b55-88d5-42d534ede493 MEDIUM 4.3 The Team Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
f18b1276-3f43-447d-8251-095c2dd57938 MEDIUM 4.3 The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … wordfence
f170379e-e833-42e0-96fd-1e1722a8331c
< 2.8.8
MEDIUM 4.3 The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… wordfence
f16b11b0-11df-4fb7-a6af-123f6c09d791
< 2.1.9
MEDIUM 4.3 The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
f15b4596-8e00-4e66-8b51-f49ede1ff307 MEDIUM 4.3 The Refund Request for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
f132b264-6e32-49d1-9733-f4a7c35dcdec
< 2.0.7
MEDIUM 4.3 The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … wordfence
f131ea1e-d652-4854-abea-6a307ca8118f
< 1.6.3
MEDIUM 4.3 The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modificat… wordfence
f12abcb2-37c1-4e2a-b947-74c50f49c6a4 MEDIUM 4.3 The FormFacade plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1.… wordfence
f10f6b12-5bf0-475a-ad9e-084ce5801b84
< 7.11.28
MEDIUM 4.3 The WP Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.… wordfence
← Prev 1355 1356 1357 1358 1359 1360 1361 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top