πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1374 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dfbf2556-0509-4d8a-8949-494c6bc82ea1
< 1.0.23
MEDIUM 4.3 The Admin Bar Remover plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
dfbdb5a7-e949-4d3a-8c8d-5dc6702f4675
< 2.12.2
MEDIUM 4.3 The OptinMonster plugin for WordPress is vulnerable to unauthorized access of data due to insufficient post type validat… wordfence
dfbc304d-624d-4558-b69e-077ee0b8aef3 MEDIUM 4.3 The Cache control by Cacholong plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
dfbaa3e4-40c2-41d8-996c-232e27a04b73
< 3.16.5
MEDIUM 4.3 The Smush plugin for WordPress is vulnerable to unauthorized deletion of the resmush list due to a missing capability ch… wordfence
dfb820f4-3d56-4f3e-96b9-206fd803c706 MEDIUM 4.3 The Trusona for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
dfb760fb-f281-4649-9bd3-92f8e281f07e
< 1.3.15
MEDIUM 4.3 The Yuki theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 1.3.14. Th… wordfence
dfa14214-26a9-4422-9d96-5357b4eed44f MEDIUM 4.3 The AnyRoad plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2. Th… wordfence
df911497-8504-424e-8717-42d0bb6c90f1
< 2.2.9
MEDIUM 4.3 The Product Gallery Slider for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
df810ea1-3d54-415b-9401-25ac99d9c740
< 1.2.1
MEDIUM 4.3 The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Cross-Site … wordfence
df7eca9b-e353-49e7-8706-89c1787637e9
< 10.5.3
MEDIUM 4.3 The WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 10.5.3 (exclusive… wordfence
df7e57a7-ba15-4181-89f9-e3f1f5de36cf MEDIUM 4.3 The VM Menu Reorder plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
df7094e5-bccd-471c-8ba1-c8a6b145b957 MEDIUM 4.3 The Sur.ly plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
df681544-f64b-4590-a377-08b05693ff1f
< 3.7.5
MEDIUM 4.3 The WP Post Author plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the aw… wordfence
df65af54-ce55-4c50-8a62-5541a1879ad4
< 7.1.2
MEDIUM 4.3 The Booster Plus for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabi… wordfence
df6080e0-2b00-4df6-849a-c24db9200ada MEDIUM 4.3 The Ultimate Security Checker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
df41b8d9-cd0e-4758-b569-2615438b8eba
< 3.5.3
MEDIUM 4.3 The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
df413b9d-5c22-4276-a11b-4f193c48740d
< 1.3.0
MEDIUM 4.3 The HT Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.9.… wordfence
df326ccb-97b0-4b8b-939b-c976cf9995e6 MEDIUM 4.3 The WP Hide Admin Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
df1a3425-b1d7-4914-ab19-c215d4e845ea
< 1.6.3
MEDIUM 4.3 The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
df0dc77e-3b15-4f9c-bcc3-f2ca78fd2280 MEDIUM 4.3 The WPVN – Username Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
df0b25cb-5233-412d-8704-63f037b4fcec
< 7.4.4
MEDIUM 4.3 The Directorist for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 7.4.3. This can… wordfence
df05f31f-85ee-42e3-97b7-c3c11f2ab2b4
< 1.6.4
MEDIUM 4.3 The WP Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
df04f598-941f-4a85-a7e0-948213f6e815 MEDIUM 4.3 The WP Customer Area plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
def6980f-5046-437e-89ae-4302e89b2276
< 1.5.4
MEDIUM 4.3 The Email marketing for WordPress by GetResponse Official plugin for WordPress is vulnerable to Sensitive Information Ex… wordfence
deebcfc0-a79b-4de1-84f6-cb9dfffce823 MEDIUM 4.3 The SMM API plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
← Prev 1371 1372 1373 1374 1375 1376 1377 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top