πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1362 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ed1aae32-6040-4c42-b8a7-4c3be371a8c0
< 2.3.42
MEDIUM 4.3 The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorize… wordfence
ed18e919-eec9-4907-93d4-a95d9a95395b
< 7.3.8
MEDIUM 4.3 The Titan Anti-spam & Security plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
ecfdd114-b7bb-45bf-84df-a92f10b2fd81 MEDIUM 4.3 The Google Site Verification plugin using Meta Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
ecfa530c-a164-4215-b68a-7be81be3fd48 MEDIUM 4.3 The ColorWay Theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.3. Th… wordfence
ecf73f3a-5f7b-4ef4-a31a-f282b953f294
< .51.1
MEDIUM 4.3 Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin befo… wordfence
ece9e89c-99d5-446d-a189-21848d75c273 MEDIUM 4.3 The Point theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is… wordfence
ece4eca1-9dc1-4f17-92e4-8b2e3e1a7306
< 3.19.18
MEDIUM 4.3 The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
ecd504ad-8812-46ec-be18-e98d05982312
< 1.0.14
MEDIUM 4.3 The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to Cross-Site R… wordfence
ecc8996a-d95c-4711-ac7d-523f5100c7fc
< 3.19.3
MEDIUM 4.3 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u… wordfence
ecc00cbc-ec65-4664-8ec6-8cfb47196ec1
< 3.18.11
MEDIUM 4.3 The WPPizza plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
ecae15fc-4842-43a0-b5a3-da50cf42d9ad MEDIUM 4.3 The Grider for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
ec6ea6e7-9c43-4b58-a1df-947a3aa7cd54
< 3.1.1
MEDIUM 4.3 The Embed Google Fonts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
ec57e0b2-61b0-4b67-9784-dbb4e6c4e4a6
< 1.4.4
MEDIUM 4.3 The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, … wordfence
ec56fc7e-9752-4418-87b2-b27b09cf2654
< 3.2.2
MEDIUM 4.3 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Cross-Si… wordfence
ec4bc1d4-2f14-4f3e-85ed-8737c56f905c
< 2.2.0
MEDIUM 4.3 The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable to unauthorized c… wordfence
ec3f2bf3-4fa5-4ee5-901c-c72a73a1ec8b
< 1.0.253
MEDIUM 4.3 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Sensitive Information … wordfence
ec395e79-b82a-45c3-a704-a15a5efaf26d
< 4.3.2
MEDIUM 4.3 The AWP Classifieds plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… wordfence
ec3667ac-1d1f-4faf-923c-7e55c03db3da MEDIUM 4.3 The Related Posts Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
ec311df2-33af-4b91-80a1-252d934c7f61
< 5.00
MEDIUM 4.3 The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to unauthorized access of data du… wordfence
ec29e5fc-5635-4809-9bb5-cd28f7fac17e
< 4.2
MEDIUM 4.3 The Login With Ajax plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… wordfence
ec1ee47d-020c-482d-ad6f-663d78e624b8
< 1.0.9
MEDIUM 4.3 The Absolute Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
ec1461a9-4504-4e60-9e38-a7257666e699
< 3.12.16
MEDIUM 4.3 The Whydonate – FREE Donate button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
ebf5537d-d80e-4844-8ed4-480f4a533439
< 1.0.6
MEDIUM 4.3 The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Inse… wordfence
ebf2e701-9f9b-4a78-a61a-0cf90cdd9755
< 1.2.91
MEDIUM 4.3 The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
ebea0ec0-f7ee-41c5-b0a5-a78e9cd11d41
< 1.1.5
MEDIUM 4.3 The Superb Social Media Share Buttons and Follow Buttons plugin for WordPress is vulnerable to Cross-Site Request Forger… wordfence
← Prev 1359 1360 1361 1362 1363 1364 1365 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top