πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1377 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dc762385-a099-4bec-9b30-ebbbc00faaeb
< 6.5.1.5
MEDIUM 4.3 The The Events Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
dc6f46b6-6832-4ccc-8272-2c470621f644
< 3.0.1
MEDIUM 4.3 The Cool Author Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… wordfence
dc6a1a39-509a-4c82-8111-f05573d0f88b
< 6.7.1
MEDIUM 4.3 The The Events Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
dc5c511f-dc79-468b-a107-cdf50999faf8
< 2.33.4
MEDIUM 4.3 The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. Th… wordfence
dc4234e3-4e0d-401d-8212-9c1817c86578 MEDIUM 4.3 The Grand Restaurant WordPress theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
dc3e89e5-2e7e-497e-b340-b787ebdf3711
< 1.2.0
MEDIUM 4.3 The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for W… wordfence
dc339d68-4b09-4721-a216-e94e29f872cc
< 2.8.7
MEDIUM 4.3 The WP Email Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
dc296d26-0727-4557-b779-b426fbaa82d8 MEDIUM 4.3 The Slider Path for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
dc260bf2-843d-4a11-a0a5-3fcc2e6bf556 MEDIUM 4.3 The ClipLink plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.… wordfence
dc2356b2-e153-4e80-bfac-c25c15cdc259
< 1.3.0
MEDIUM 4.3 The Media Library Helper by Codexin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
dc1681a8-5f2e-45f1-96d9-797b13644607 MEDIUM 4.3 The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
dc138cbb-2713-4b0a-8e3a-8e1a9266637f
< 3.4.26
MEDIUM 4.3 The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to… wordfence
dc0e9fab-0b8f-419d-a799-06297b24df33
< 1.2.8
MEDIUM 4.3 The Advanced Notifications plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
dc0cee75-9c5d-455f-b77f-9ce643aeed19
< 3.2.25
MEDIUM 4.3 The VPSUForm – Drag & Drop Contact Form Builder with Email Automation plugin for WordPress is vulnerable to Sensitive … wordfence
dc07620e-23fe-4039-a6f5-e0b320424444 MEDIUM 4.3 The Newsletter Popup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
dc052b00-65a7-4668-8bdd-b06d69d12a4a
< 1.0.1
MEDIUM 4.3 The video carousel slider with lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0.… wordfence
dbfe3f7d-d653-421b-a054-a4ab266866c3
< 2.12.2
MEDIUM 4.3 The Payment Gateway Based Fees and Discounts for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Fo… wordfence
dbf8c216-aedd-4db9-aaa4-61bc0d7850cb
< 1.5
MEDIUM 4.3 The XLTab – Accordions and Tabs for Elementor Page Builder plugin for WordPress is vulnerable to Information Exposure … wordfence
dbf54852-f3fe-4c9e-9348-44a73f9a8131
< 1.6.12
MEDIUM 4.3 The Parcel Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
dbf196d0-a778-483b-9475-0c2333f2284e
< 5.5.1
MEDIUM 4.3 The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable … wordfence
dbe8d453-21f0-43e2-84d3-3c520ab9c308
< 2.0.0
MEDIUM 4.3 The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1… wordfence
dbddf8a5-57fe-4c70-b564-75e62b96462d
< 3.3.11
MEDIUM 4.3 The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to unauthorized modification of data due to … wordfence
dbcd3ddd-a729-4183-a6c0-f50390b31332 MEDIUM 4.3 The Woo Product Feed For Marketing Channels plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
dbc60daa-c093-4cd6-8f07-d9015e2bd957
< 2.2.4
MEDIUM 4.3 The Carousel Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
dbba79d1-177c-4a7f-9ae6-5fc9a15cd599 MEDIUM 4.3 The RDP Wiki Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
← Prev 1374 1375 1376 1377 1378 1379 1380 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top