πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1367 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e764e567-524e-40b9-aa9f-653a5553375d
< 2.4.6
MEDIUM 4.3 The Participants Database plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
e76447ec-2815-4758-ae2c-67a938a739d9
< 5.5.5
MEDIUM 4.3 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
e760cb9a-5e16-47bd-881b-26c7e7a02e81 MEDIUM 4.3 The WP Custom Widget area plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
e757ca2f-c4d9-4747-9f84-75ef8a54d485
< 1.9.0
MEDIUM 4.3 The PeproDev CF7 Database plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
e74ff260-48af-4fc2-80d8-1ff2403f8f33
< 2.2.10
MEDIUM 4.3 The Taxonomy filter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
e74e1a7c-4fe6-4041-8c4c-13389dacb9db MEDIUM 4.3 The WooMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized loss of data due to a miss… wordfence
e743e656-2dd9-43ed-a190-b03af7c75c54
< 5.14.2
MEDIUM 4.3 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
e73c7762-c51f-4896-8ee8-243573e387fc MEDIUM 4.3 The WN Flipbox Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
e732031f-378a-4e71-8559-19c5e957d38b
< 1.5.8
MEDIUM 4.3 The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a… wordfence
e728a6e4-e9bf-4672-b1a5-e00b6ac0cded
< 2.0.1
MEDIUM 4.3 The jobzilla theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. … wordfence
e7203b5c-5753-453c-8fc2-26fcebdeea5b
< 3.9.3
MEDIUM 4.3 The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.2. Thi… wordfence
e7113b1c-78dc-4648-b14a-52ff6668fd1d
< 3.0.11
MEDIUM 4.3 The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized… wordfence
e709eb98-d814-45aa-baeb-90a1d7471bcc MEDIUM 4.3 The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
e700a02f-21a7-4786-b7a7-d0c83a9314e3 MEDIUM 4.3 The ILC Thickbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
e6d5036a-c756-47a6-b071-c393f8a6ce5e MEDIUM 4.3 Multiple plugins and/or themes for WordPress by KlbTheme are vulnerable to Cross-Site Request Forgery in various version… wordfence
e6d195cd-4df8-4926-b834-d695fc05f81d
< 8.2.1
MEDIUM 4.3 The Slider Hero plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.0… wordfence
e6bb3680-0623-4633-971e-3bc4a52dfad3
< 1.1.6
MEDIUM 4.3 The WP Show Posts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on… wordfence
e6a7ec29-6dc6-4c73-8cc4-4aa4da79941e
< 4.13.2
MEDIUM 4.3 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery… wordfence
e6a2b2f6-c648-4755-be24-92c7f287813e
< 4.5.7
MEDIUM 4.3 The Razorpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
e69a06a1-f1a2-4cb0-b8e5-fba850739b57 MEDIUM 4.3 The Eagle Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3… wordfence
e68a3487-4436-4c44-9833-689c86a08bc8
< 6.30.31
MEDIUM 4.3 The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Fo… wordfence
e67c6c3f-0b2a-424f-b8f2-2771449c82b4 MEDIUM 4.3 The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
e6499f46-b3b6-496f-a9bc-531bcbba2418
< 1.3.2
MEDIUM 4.3 The WP Sort Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
e641453c-8fa0-4b44-b912-b797aeae1795
< 7.3.4
MEDIUM 4.3 The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could a… wordfence
e62fa16f-a4a1-44a7-9a66-abafd8dddf67
< 12.7
MEDIUM 4.3 The Jetpack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
← Prev 1364 1365 1366 1367 1368 1369 1370 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top