πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1371 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e35dcd3a-651e-4984-8362-95503ff8c546
< 3.2.1
MEDIUM 4.3 The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for Wo… wordfence
e358c32d-6d0b-421d-9746-aafa1252dcea
< 1.8.0
MEDIUM 4.3 The Site Kit by Google plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and inc… wordfence
e358355e-097c-4a6d-a21a-3d08098efff0
< 7.20
MEDIUM 4.3 The W3SPEEDSTER plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7… wordfence
e336dc27-4a76-4197-929c-b221f42bfe69
< 1.0.9
MEDIUM 4.3 The Dam Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… wordfence
e31bf122-e3b0-43d4-afff-f3baf3aa53e6 MEDIUM 4.3 The Shantz WordPress QOTD for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
e30e64e7-5de9-4eb3-914f-457daa6f3fe5
< 1.3.6
MEDIUM 4.3 The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
e30379bf-0ea1-4443-81bb-4337a0311ed3 MEDIUM 4.3 The Quran Translations plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
e2f497a7-30d5-453f-96d4-11297a138761 MEDIUM 4.3 The WP Show Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
e2c1606e-b6b6-4f7d-8473-1015677ded7c
< 4.1
MEDIUM 4.3 The WP EasyPay plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.4.… wordfence
e2bd8eec-5984-42f8-ba9a-ce61bf7cd440
< 1.4.5
MEDIUM 4.3 The Organization chart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
e29dac44-5c85-4f73-ae96-4bc0deca64f4
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
e28a54a0-74c7-4d39-a846-65bf98d055ab
< 1.0.7
MEDIUM 4.3 The Maintenance Notice plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
e27224aa-56c4-49ab-b9b3-b431b38e126e
< 5.62.0
MEDIUM 4.3 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… wordfence
e2719afc-e52c-4fcc-b030-2f6aaddb5ab9
< 3.4.2
MEDIUM 4.3 The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
e26d4914-23fd-4e93-a08a-7e9dd5222a73
< 2.0.4
MEDIUM 4.3 The Nexter theme for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on se… wordfence
e2619d50-e295-4e13-91d4-f998b8aa5be4
< 2.8.0
MEDIUM 4.3 The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capabil… wordfence
e23e52d7-871f-46fc-bd71-60a9f50a22e1
< 2.6.0
MEDIUM 4.3 The Buddyboss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and… wordfence
e23739b7-be36-441d-9b73-f51a0184a465
< 2.6.7.2
MEDIUM 4.3 The ApplyOnline – Application Form Builder and Manager plugin for WordPress is vulnerable to unauthorized access due t… wordfence
e235dd5e-09b2-4fcd-af32-ff9bcf51954d
< 2.10.3
MEDIUM 4.3 The WooCommerce Ultimate Points And Rewards plugin for WordPress is vulnerable to Sensitive Information Exposure in all … wordfence
e234a79d-5d46-44db-833c-51e202dc49bf MEDIUM 4.3 The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu… wordfence
e233f47f-734f-4190-ac5f-b63d54ebd4a8
< 4.3.4
MEDIUM 4.3 The Extra Fees Plugin for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
e2273c53-bc8a-45c7-914d-a3b934c2cb18
< 3.2.3
MEDIUM 4.3 The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to Cro… wordfence
e226d75f-37b2-4af2-bba0-0fd3a96cc1a0
< 3.3.6
MEDIUM 4.3 The Video Gallery & Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
e2263cf4-8dd8-4cb2-9355-8e864225f5f0 MEDIUM 4.3 The FanBridge signup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
e21656a6-5442-4a1b-866e-eba442509896
< 2.2.1
MEDIUM 4.3 The Crowdfunding plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… wordfence
← Prev 1368 1369 1370 1371 1372 1373 1374 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top