๐Ÿ›ก๏ธ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1372 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e2159209-d220-4a80-bc67-430d37a16dea
< 1.16.7
MEDIUM 4.3 The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… wordfence
e214fadf-73fd-430f-8608-6630ce82b78c
< 4.1.3
MEDIUM 4.3 The Eazy Plugin Manager โ€“ Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to unau… wordfence
e211df80-aab7-43a1-8c11-a472f90ef4c6
< 2.7.1
MEDIUM 4.3 The Image Slider by Ays- Responsive Slider and Carousel plugin for WordPress is vulnerable to Cross-Site Request Forgery… wordfence
e2008e0b-32c6-46fb-93b9-2b0004f478e8
< 4.5.2
MEDIUM 4.3 The WP Activity Log for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.0. T… wordfence
e1fcc06a-9571-44c3-b3ff-286ccda1abea
< 0.6.0
MEDIUM 4.3 The Force Update Translations plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
e1fa3569-9a9a-4aa6-9057-c87601fadb9f MEDIUM 4.3 The Clever Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up … wordfence
e1ed77cf-2595-477a-af86-25c917817984
< 2.6.4.1
MEDIUM 4.3 The WC Vendors โ€“ WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable … wordfence
e1ecc237-87b0-4c4d-94cc-d3af9c6669c5
< 1.4.02
MEDIUM 4.3 The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to,… wordfence
e1d7e024-83c5-40c2-986d-cfa69c10041e
< 2.0.15.1
MEDIUM 4.3 The JetPopup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, … wordfence
e1d0af55-eee4-4283-8216-0474c65deac7 MEDIUM 4.3 The Recent Posts From Each Category plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
e1cab43e-8710-4150-935a-5268170d14ad MEDIUM 4.3 The ็•…่จ€่ฏ„่ฎบ็ณป็ปŸ plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
e1c9cfba-d0dd-414a-b464-911c2188d96f
< 3.54.5
MEDIUM 4.3 The WordLift โ€“ AI powered SEO โ€“ Schema plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
e1b70dc7-6be5-48fc-b3c3-6bd45a5b7992 MEDIUM 4.3 The Shortcodes and extra features for Phlox plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
e1a492f6-8248-4a84-b163-7262b02563c2
< 2.2.1
MEDIUM 4.3 The MBE eShip plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.2. … wordfence
e1a1df7e-1a57-45b3-a4b3-cb3218782ad9 MEDIUM 4.3 The Download Panel plugin for WordPress is vulnerable to unauthorized settings modification due to a missing capability … wordfence
e1900948-8813-4c88-87fe-ddf830c6ae3b
< 5.3.1
MEDIUM 4.3 The LiteSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
e188c944-7f04-4977-b13a-54caa5e91fd6 MEDIUM 4.3 The Graphist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
e15d7310-90b0-410e-b758-6b142c70d111
< 1.5.16
MEDIUM 4.3 The Wallet for WooCommerce plugin for WordPress is vulnerable to a race condition in all versions up to, and including, … wordfence
e148a10a-fe0b-468f-8319-956d318891f8
< 1.2.29
MEDIUM 4.3 The Fastly plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.28. Th… wordfence
e13a38d0-9781-4b1e-8b2b-fdcb1001b8d5
< 1.12.5
MEDIUM 4.3 The Giveaways and Contests by RafflePress plugin for WordPress is vulnerable to unauthorized access of data due to a mis… wordfence
e13379a9-fe21-4fb5-a53e-c86eef8cac54
< 2.3
MEDIUM 4.3 The Recover abandoned cart for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
e11ceba3-6bf4-4759-a8ac-ca779e2924cd
< 2.5
MEDIUM 4.3 The Muslim Prayer Time BD plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
e1179303-fe7c-47f1-958c-2e4d2c574e4a
< 2.5.3
MEDIUM 4.3 The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for … wordfence
e1120811-e0da-4dec-9723-0fdbd86efe67
< 3.6.34
MEDIUM 4.3 The My auctions allegro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
e103f59a-00fa-4d4c-b4fc-834754886d49
< 4.13.2
MEDIUM 4.3 The ProfilePress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.13… wordfence
← Prev 1369 1370 1371 1372 1373 1374 1375 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top