πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1364 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
eab422b8-8cf5-441e-a21f-6a0e1b7642b2
< 2.14.1
MEDIUM 4.3 The AffiliateWP for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th… wordfence
ea9fff3a-c1ac-4599-aff7-d9593b74749d MEDIUM 4.3 The NetInsight Analytics Implementation Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… wordfence
ea9bff20-acbc-4f94-8684-516a8472d0cc MEDIUM 4.3 The Cookie Warning plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
ea984974-2835-4bad-b7ca-975ad21c80e5
< 1.0.96
MEDIUM 4.3 The Amelia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.95. Th… wordfence
ea91769f-244c-4b11-a6e3-ea78e60b4e32
< 4.6.5
MEDIUM 4.3 The Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode plugin for WordPress is vu… wordfence
ea89d3ed-b0c7-40fb-8c9f-cfa0028fa6c2
< 5.15.7
MEDIUM 4.3 The Avada Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.15.6… wordfence
ea85fa9a-78ea-4017-b72e-49db7eafa11e MEDIUM 4.3 The Galleria plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.3. T… wordfence
ea595e78-f4fc-491d-8143-c836302618d5 MEDIUM 4.3 The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_co… wordfence
ea41c631-c016-400b-9f68-63aa661ced43 MEDIUM 4.3 The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
ea38e16f-4012-4d22-9a47-76f91251e1d7
< 2.8.21
MEDIUM 4.3 The System Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
ea1f1825-241c-4060-a1e1-a13f92421fef MEDIUM 4.3 The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-S… wordfence
ea1d2448-76da-4992-98f6-9898697602ba
< 2.3.15
MEDIUM 4.3 The OnePress theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
ea13aebb-c853-4828-8d7f-b607aa83b702
< 2.7.7
MEDIUM 4.3 In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application … wordfence
ea0d92c7-c247-401d-8cfa-bf42a0692fcd
< 7.1.8
MEDIUM 4.3 The FS Poster plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several fun… wordfence
ea073543-20b5-48ec-b9d4-751a674d8273
< 3.2.11
MEDIUM 4.3 The advanced-database-cleaner-pro plugin for WordPress is vulnerable to Path Traversal in all versions up to, and includ… wordfence
e9e4ffa9-9f61-42e8-85f5-1dea499a63f7 MEDIUM 4.3 The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
e9dea663-c3ee-4dda-85c1-5cec970adfba
< 3.5.2
MEDIUM 4.3 The Notification for Telegram plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
e9d1a33b-2518-48f7-90b6-a94a34473d1e
< 2.8.8
MEDIUM 4.3 The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… wordfence
e9c19aa6-a075-48d2-8196-a011f5efefc5
< 1.7.6
MEDIUM 4.3 The Organization chart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
e9b3f1ff-4f8b-45ec-90eb-1a75353654e3
< 1.7.58
MEDIUM 4.3 The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Path Traversa… wordfence
e9a28625-19e4-4696-bb51-7115368120d3 MEDIUM 4.3 The WP-Cache.com plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.… wordfence
e9a1de53-330f-49ab-a8f8-22753c62bd36
< 3.6.6
MEDIUM 4.3 The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) pl… wordfence
e99ed03f-ed0a-4f17-b9fe-db0a0e573ed2 MEDIUM 4.3 The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
e98d4f04-74cd-486f-bb2f-fad76895f386
< 1.0.2
MEDIUM 4.3 The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec… wordfence
e98aa389-9113-4997-8b96-1ca03cdfc235
< 1.6
MEDIUM 4.3 The Mobile Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5… wordfence
← Prev 1361 1362 1363 1364 1365 1366 1367 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top