πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1369 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e573648e-215f-4858-a4d3-a3e85119dbcf
< 6.0.1
MEDIUM 4.3 The FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor plugin for Wo… wordfence
e56d98b5-ae38-4059-bc32-d0fffd326740
< 7.1.7
MEDIUM 4.3 The Theme My Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
e5665931-8da9-44db-a5b1-46acebf14f3b
< 2.32
MEDIUM 4.3 The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
e5575725-99ba-4499-93e5-f7648c82ac52
< 2.126
MEDIUM 4.3 The MyCryptoCheckout plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
e53c764c-c4a0-49f7-a603-d7e2a9d13ad5 MEDIUM 4.3 The Competition Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
e52e7078-3717-44d1-a5e1-ce41d1333baa
< 20.0
MEDIUM 4.3 The Image Caption Hover Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
e5167635-6f60-4657-b371-bb00680d1e49
< 5.6.1
MEDIUM 4.3 The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized access due to a … wordfence
e505b376-89ca-4df1-85a1-f8c472325547
< 1.2.8
MEDIUM 4.3 The Plugin Notes Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
e500a5e4-f3f2-4732-a861-3c8d66f8ebfa
< 4.4.22
MEDIUM 4.3 The Customizr theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.21. … wordfence
e4f0fdaf-a3b3-4ffe-aa18-ecd7c3a33513
< 2.6.1
MEDIUM 4.3 The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to unauthorized access due to a m… wordfence
e4ed8c6e-5f80-4360-9478-fff49b1fee94
< 21.2.9
MEDIUM 4.3 The Contest Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
e4dc8f18-d990-4e41-8bf8-dfa9de4c0f6e
< 2.1.6
MEDIUM 4.3 The WP Crowdfunding plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
e4d2281a-7cbd-445e-8bb6-cfb72d7133c5 MEDIUM 4.3 The WPMK PDF Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
e4cf42d3-9864-440b-8357-36c82cbef28f
< 3.2.25
MEDIUM 4.3 The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up… wordfence
e4b9eeb9-7ce4-446d-8ac0-af9cea0c893a
< 3.0.6
MEDIUM 4.3 The Affiliate Booster – Pros & Cons, Notice, and CTA Blocks for Affiliates plugin for WordPress is vulnerable to Cross… wordfence
e4a32fdc-1c72-45fc-bb57-44f6888e0885
< 1.8.2
MEDIUM 4.3 The Mang Board WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8… wordfence
e49e7cdf-93ca-415f-ba83-986cbb869220
< 1.1.4
MEDIUM 4.3 The Increase Maximum Upload File Size | Increase Execution Time plugin for WordPress is vulnerable to Full Path Disclosu… wordfence
e4986b06-f5a5-4d0a-8e7b-924ec24b090c
< 0.7.3
MEDIUM 4.3 The Paid Memberships Pro - Add Member From Admin plugin for WordPress is vulnerable to Cross-Site Request Forgery in ver… wordfence
e495c215-2e01-4a37-aca3-99a067c46791
< 5.1.8
MEDIUM 4.3 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress … wordfence
e4785012-d160-42cc-bd06-d9b8e65652a4
< 1.1.121
MEDIUM 4.3 The Calculated Fields Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
e466640e-de66-42f0-b56b-226db32d382d MEDIUM 4.3 The Whatsiplus Scheduled Notification for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
e46513d2-65d0-4215-99a7-051603ec4569 MEDIUM 4.3 The AdFoxly – Ad Manager, AdSense Ads & Ads.txt plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… wordfence
e462a7ba-887c-408d-87a6-9260a33dcff5
< 1.1.5
MEDIUM 4.3 The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i… wordfence
e45bcb67-5ea7-48e7-bf65-e26416866530 MEDIUM 4.3 The Backwp plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2.… wordfence
e456b08d-ccb9-40b8-9c36-d4b2f7f7fb91 MEDIUM 4.3 The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
← Prev 1366 1367 1368 1369 1370 1371 1372 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top