πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1373 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e0f98cf4-2f34-49b6-a974-2ff1e5a794aa MEDIUM 4.3 The WP Media File Type Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
e0ef8c54-2ac3-4fcc-9ae1-8b23f4d061cd
< 4.15.2
MEDIUM 4.3 The oik plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all… wordfence
e0e5e143-c4de-4312-8c8b-acf7ef60e0d5
< 3.0.2
MEDIUM 4.3 The Internal Links Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
e0d1b675-7b9a-49ff-a308-075fefca9743
< 5.6.5
MEDIUM 4.3 The WP Activity Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5… wordfence
e0ccdc0d-7c38-4dd3-be39-2359d63b2b6c
< 3.1.11
MEDIUM 4.3 The Strong Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
e0bfa461-5cea-40e8-af9f-800cdbb6efb5 MEDIUM 4.3 The WooDiscuz – WooCommerce Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
e0bf0bf1-91c3-4f91-b5e4-189944b6a557
< 4.5.5
MEDIUM 4.3 The BEAF plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.4. This … wordfence
e0b571c8-d414-4566-a24c-e70fd1740256
< 4.0.9
MEDIUM 4.3 The Widget Options plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
e0af864b-75aa-4384-b461-50bb11cfbf79
< 2.0.7
MEDIUM 4.3 The Revive.so – Bulk Rewrite and Republish Blog Posts plugin for WordPress is vulnerable to unauthorized access due to… wordfence
e099d8e2-6305-43fc-8807-a37791deb2ff
< 1.3.1
MEDIUM 4.3 The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPres… wordfence
e0981349-e627-4a3c-9972-01111a6b6140 MEDIUM 4.3 The Custom Order Statuses for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
e07649c0-b2eb-421b-95ae-a9530524470a
< 3.6.7
MEDIUM 4.3 The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have authorisation and CSRF checks in its co… wordfence
e070b422-9036-4362-832b-43fd4838f394
< 3.1.88
MEDIUM 4.3 The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerab… wordfence
e051a83e-ad5a-4789-bfee-e03aa9d6a3fc
< 4.5.1
MEDIUM 4.3 The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all … wordfence
e03f95ae-c1ba-4679-888b-055293e1351f
< 3.2.8
MEDIUM 4.3 The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
e03e952a-2cde-413a-9d0a-9046772c0dc0 MEDIUM 4.3 The JS Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc… wordfence
e03390e5-5604-4b9d-ab1b-dac2b19270cd
< 3.1.0
MEDIUM 4.3 The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
e02597b1-eea6-4fdd-baeb-527201d1c61f
< 2.4.8
MEDIUM 4.3 The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to un… wordfence
e018ca7c-06dd-4d40-91d4-4ed188b8aaf2
< 2.0.21
MEDIUM 4.3 The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
e00c12ae-3b9d-45b6-b8db-eeaaeb97bfee MEDIUM 4.3 The Rewrite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.1… wordfence
e00672e0-ce3a-45ac-9901-7497eb1cc1a2
< 5.4.4
MEDIUM 4.3 The Classified Listing plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
e0050d44-bfa1-4dcb-947b-0df1b5e826d3
< 1.20
MEDIUM 4.3 The Sertifier Certificate & Badge Maker for WordPress – Tutor LMS plugin for WordPress is vulnerable to Cross-Site Req… wordfence
dfe6f49a-1dd1-46d9-8e15-a8a766917092
< 1.1.6
MEDIUM 4.3 The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site… wordfence
dfd95489-c1d5-45cc-8ac4-400a39391aa2
< 3.7.2
MEDIUM 4.3 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access due to … wordfence
dfcc2ab2-504d-4151-9435-618e317ce95c
< 2.16.7
MEDIUM 4.3 The Seraphinite Post .DOCX Source plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
← Prev 1370 1371 1372 1373 1374 1375 1376 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top