πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1360 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
efaef405-9721-4fb6-bcb4-4bd4f78742fd MEDIUM 4.3 The WP Tiles plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.1.… wordfence
efadd529-f369-4c7a-ab71-170e72c997f1
< 3.2
MEDIUM 4.3 The WP Custom Cursors plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 3.2. This is du… wordfence
efa9b44d-8b6c-4a11-82af-cecc2c202024 MEDIUM 4.3 The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
efa646ee-ebee-4528-a421-09ee3dc8275a
< 2.8.0
MEDIUM 4.3 The bitformpro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… wordfence
efa4b67c-1bb8-413a-8cb8-039168b0b586
< 1.0.6
MEDIUM 4.3 The Chankhe theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … wordfence
ef926bc7-b50f-40ac-9ace-7e01b26f34e1
< 2.1.0
MEDIUM 4.3 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorizat… wordfence
ef8c41c6-3065-4650-81e9-bdba0e38f2bd
< 5.6.8
MEDIUM 4.3 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… wordfence
ef7ec175-cee5-4559-909d-ee689158d67c
< 1.14
MEDIUM 4.3 The League Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.13… wordfence
ef7cf633-e907-4da1-bd96-0013e88defbb
< 2.1.8
MEDIUM 4.3 The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.7… wordfence
ef5f99ca-8a0d-4ec4-8b59-c0c4637dfbc3
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
ef528553-4037-43e0-af2d-8324412147f3
< 12.7
MEDIUM 4.3 The MihanPanel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 12.7. This is due to m… wordfence
ef480fce-d0e3-47af-92ea-2c84c3f8e2f7
< 2.2.7
MEDIUM 4.3 The Popup Box – new WordPress popup plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
ef47feb7-76fd-470d-ba48-55ba3c323c6d
< 1.9.3
MEDIUM 4.3 The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to unauthorized modification … wordfence
ef176a6c-33d1-45d6-8a1d-3df1e8eb2170 MEDIUM 4.3 The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.… wordfence
ef1362b5-576d-4d22-ad5d-89f38e8e3743 MEDIUM 4.3 The Business Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
ef014597-dd85-4ac0-a08d-de60b34ab4c9 MEDIUM 4.3 The Bulk Content Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
eef7f964-8330-4c57-a5f4-0280853dcf76
< 2.24.4
MEDIUM 4.3 The Internal Link Juicer: SEO Auto Linker for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery… wordfence
eef0796f-f56d-4be3-8fbd-010ac0fb3448
< 1.5.2
MEDIUM 4.3 The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on… wordfence
eec9ae40-3a76-4208-8348-4a9ef72fc918
< 16.9
MEDIUM 4.3 The Malcure Malware Scanner β€” #1 Toolset for Malware Removal plugin for WordPress is vulnerable to unauthorized access… wordfence
eeacc903-9be2-4333-9528-d98707d1df55
< 1.5.4
MEDIUM 4.3 The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
eea33d0b-2547-4c51-8c4c-d178d6c8502d
< 3.12.28
MEDIUM 4.3 The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3… wordfence
ee7c679e-392c-40cd-b768-d78fae6065bb MEDIUM 4.3 The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
ee73937c-8a97-4afd-a0f6-d5e9caddc82c MEDIUM 4.3 The Enable Latex plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
ee6ffb62-0dfd-40c1-8fde-8705d99d4144
< 2.2.6
MEDIUM 4.3 The UpsellWP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
ee5ad5d6-f38c-481a-ba0e-38481804739f MEDIUM 4.3 The More Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. … wordfence
← Prev 1357 1358 1359 1360 1361 1362 1363 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top