πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1368 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e62a58ec-4ea5-4241-8148-fc8801bd59b3 MEDIUM 4.3 The Our Services Showcase plugin for WordPress is vulnerable to authorization bypass due to a missing capability check o… wordfence
e616a2db-7249-4c7d-84f6-5fac198cebc6
< 3.1.0
MEDIUM 4.3 The Auto Prune Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
e615e08f-656e-415b-9d08-80afebffa6c8 MEDIUM 4.3 The Atelier Create CV plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
e6140ca6-7f7a-41c3-9dde-b95c85e174ad
< 2.0.0
MEDIUM 4.3 The WING WordPress Migrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
e607b1a0-9552-4822-ab8b-fb995648dae0
< 3.5.6
MEDIUM 4.3 The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to unauthoriz… wordfence
e5e191b4-ca76-4ba1-ad14-b4d501f3af95 MEDIUM 4.3 The Flipdish Ordering System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
e5c87ae0-9a53-4292-a4d3-05b3bdb37b71 MEDIUM 4.3 The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to authorization bypass due to a missing cap… wordfence
e5c86f72-934c-4f3b-ab2a-65df1490ca8a
< 3.0.9
MEDIUM 4.3 The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all ve… wordfence
e5c0ff52-57c2-447f-bb22-2079607c3217
< 3.3.29
MEDIUM 4.3 The eCommerce Product Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
e5bab390-1590-44f2-8c65-bc329955ed84
< 5.12.3
MEDIUM 4.3 The Advanced Custom Fields plugin for WordPress has a file upload vulnerability in versions up to, and including, 5.12.2… wordfence
e5b6a5ee-33ad-4062-a234-4ce19124d3b7 MEDIUM 4.3 The Ultimate Learning Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
e5b4c494-1188-44e2-b07d-5f4d45b36b45
< 2.2.4
MEDIUM 4.3 The Custom Twitter Feeds (Tweets Widget) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
e5a9cced-0e5e-4b6e-8291-0a862c9f9523
< 3.9.8
MEDIUM 4.3 The CHP Ads Block Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
e5a76c2b-b4c8-47aa-83ac-cc36c100d70e
< 1.5.6
MEDIUM 4.3 The Duplicate Post plugin for WordPress is vulnerable to unauthorized access in all versions up to 1.5.6. This is due to… wordfence
e5957d6b-40e5-44c4-9a1b-e9c49e175162
< 1.1.23.1
MEDIUM 4.3 The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc… wordfence
e593943a-c68f-4331-8e99-53db3a3cc9ca MEDIUM 4.3 The IDonatePro - Blood Donation, Request And Donor Management WordPress Plugin plugin for WordPress is vulnerable to Sen… wordfence
e592ee57-0ff7-4ca0-9edf-767310a6ed57 MEDIUM 4.3 The Motionger for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
e59293a6-cc61-4913-9ed0-13fa16299705 MEDIUM 4.3 The Update Theme and Plugins from Zip File plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
e5911815-db53-46f2-a16d-ed21be20bbfb
< 1.3.0
MEDIUM 4.3 The RAYS Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.2. … wordfence
e58fe046-0119-48e6-ac90-8b70d7eb9956
< 2.9.0
MEDIUM 4.3 The CM Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.9.0. This i… wordfence
e58fa0b6-22f3-4e56-96f8-d1085498a1ac
< 1.33.21
MEDIUM 4.3 The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve… wordfence
e58f2121-26c8-4364-aa2a-41de1b0216f9
< 2.1.0
MEDIUM 4.3 The Subscribe to Download plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
e57f2f91-3f6f-4452-9525-4c150a037d2f MEDIUM 4.3 The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
e57bfae5-4cc0-4d97-9431-4c8ebb2f0882
< 8.4.7
MEDIUM 4.3 The Simple Share Buttons Adder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
e573c0a4-d053-400b-828c-0d0eca880776
< 2.3.10
MEDIUM 4.3 The Woody code snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
← Prev 1365 1366 1367 1368 1369 1370 1371 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top