πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1359 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f105bee6-21b2-4014-bb0a-9e53c49e29b0
< 4.4.6
MEDIUM 4.3 The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
f0e8d029-af6b-43cb-aa90-f92777c5ac99 MEDIUM 4.3 The Timthumb Vulnerability Scanner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
f0d584d0-1709-47dd-884b-ad21cac9d537
< 4.1.20
MEDIUM 4.3 The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensi… wordfence
f0b25726-0b8e-4fce-a986-5f1e176da75a
< 4.1.6
MEDIUM 4.3 The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 4.1.6. This is … wordfence
f0af86e4-c30b-49e2-ad6a-97a415a74d18
< 2.9.5
MEDIUM 4.3 The Top 10 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.4. Th… wordfence
f08c63a0-2e8a-4ae9-abf6-5bd09c0a2073
< 4.7.1
MEDIUM 4.3 The Print Anywhere & Create PDFs of Order Receipts, Invoices, Labels & More. plugin for WordPress is vulnerable to unaut… wordfence
f079037c-cea6-4ba6-843f-99c5e5fe59a5
< 1.0.105
MEDIUM 4.3 The Search in Place plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
f0767c75-7571-46d9-b16a-2760be5a843b MEDIUM 4.3 The 6Storage Rentals plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
f065648a-436a-459c-8ab1-c948c78b43c9
< 4.4
MEDIUM 4.3 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a… wordfence
f0576cde-8d32-4f06-899a-a9ebff99d8ba
< 2.6.0
MEDIUM 4.3 The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow user… wordfence
f0543f32-54d4-4180-95c4-c9ddc0e08384
< 0.9.6.1
MEDIUM 4.3 The Inline Google Spreadsheet Viewer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
f0542cea-7550-4f51-a8b5-d313189b637a MEDIUM 4.3 The flexo-social-gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
f04ef770-73d9-4940-9736-c214bf5137ba MEDIUM 4.3 The Course Redirects for Learndash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
f03deae6-24c6-49b4-b8cc-1d80275a2952
< 1.2.8.5
MEDIUM 4.3 The Xpro Theme Builder For Elementor – FREE plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
f03dd6f4-44ca-4afe-b3fa-8770fca8a067
< 4.5.5.3
MEDIUM 4.3 The Geo My WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4… wordfence
f03cf84f-842f-4696-a152-d2fe0b23a5db MEDIUM 4.3 The Developer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6. … wordfence
f0292877-33ca-425f-a95b-547b3bed2c10
< 20.8.14
MEDIUM 4.3 The Sprout Invoices – Client Invoicing & Estimates plugin for WordPress is vulnerable to unauthorized access due to a … wordfence
f01071a6-4188-4cb4-9aa5-731b32c6960e MEDIUM 4.3 The Behance Portfolio Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
f00ca075-cbf0-428b-a53b-dc723889f69b
< 1.0.24
MEDIUM 4.3 The Email Address Encoder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
f00ac468-870a-4c43-af25-9febea5e4d67 MEDIUM 4.3 The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
f002d061-4e9d-49be-9d4c-c470ec97f653 MEDIUM 4.3 Several YITHEMES plugins for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect… wordfence
eff03dbc-1bb7-4a72-b57c-f1bde966c286
< 1.8.7
MEDIUM 4.3 The Product Table by WBW plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
efee685c-e2cd-471b-aea9-607124df6006
< 1.2.59
MEDIUM 4.3 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulner… wordfence
efe57241-2bb3-41d1-8638-b69ceaff0b4f
< 2.1.4
MEDIUM 4.3 The Alba Board plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. T… wordfence
efcf88af-9c65-4825-a248-9c29eec7031b
< 2.8.3
MEDIUM 4.3 The Serial Codes Generator and Validator with WooCommerce Support plugin for WordPress is vulnerable to unauthorized acc… wordfence
← Prev 1356 1357 1358 1359 1360 1361 1362 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top