πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1378 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
db8cfdba-f3b2-45dc-9be7-6f6374fd5f39
< 1.1.4
MEDIUM 4.3 The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
db7f5553-758b-47ab-8319-a549b73f4cfa
< 5.1.8
MEDIUM 4.3 The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
db7f4db7-c348-4a02-a3f1-93a60a9bb23d
< 2.23
MEDIUM 4.3 The Cloudflare Turnstile or reCAPTCHA For any Pages, to Block Spam and Hackers Attack. plugin for WordPress is vulnerabl… wordfence
db753659-d132-4822-8d89-821ba0b7fba1
< 1.7
MEDIUM 4.3 The Current Age Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
db707507-c53f-45b8-a8e1-7fea1c6f8f3c MEDIUM 4.3 The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish… wordfence
db664d0a-a58d-4d8b-ae0a-074f32d8710c
< 1.2.8
MEDIUM 4.3 The Decorator – WooCommerce Email Customizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… wordfence
db631db3-bac7-4f9b-8f4e-fb82ddcb8467
< 1.9.9
MEDIUM 4.3 The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
db6167c5-fdae-490f-813c-f1a0b34aa9d8 MEDIUM 4.3 The WP eCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
db5d6cc9-24d7-42bf-905e-4c3764c659ed
< 6.12.5
MEDIUM 4.3 The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
db56844f-9988-4f6a-ba1d-f190ff009f2b
< 1.0.101
MEDIUM 4.3 The Colibri WP theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0… wordfence
db48d5c0-73d0-40a2-b3b1-063d739741a8 MEDIUM 4.3 The Easy Site Importer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
db3b8394-f8c9-4630-b78e-fbfe8a3fffdb
< 2.7.10
MEDIUM 4.3 The Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Part… wordfence
db2a9b18-30f9-41b4-b96b-878071db4b1c MEDIUM 4.3 The Custom Script Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
db2a2ca9-a12c-412d-80f7-66f1dc3e09af
< 3.8.3
MEDIUM 4.3 The Newsletter plugin is susceptible to an Open Redirect vulnerability. This issue is due to the fact user input it take… wordfence
db29f17d-1d2b-4f78-a78d-1579e2a5d975
< 1.2.9
MEDIUM 4.3 The 10WebAnalytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
db27ae52-1362-4acb-9410-49ad041770f6 MEDIUM 4.3 The True Ranker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
db1e7efe-3827-4a82-be08-eae4efc23399
< 1.2.5
MEDIUM 4.3 The Connector for Gravity Forms and Google Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
db0715ed-a06e-4a68-b9c3-408887cae113 MEDIUM 4.3 The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1.… wordfence
db0508dd-143f-4674-8193-d46967d2799f
< 1.3.9
MEDIUM 4.3 The Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator plugin for WordPress is … wordfence
dafc355c-18e7-4312-bd16-8ef65ad54dad
< 2.7.16
MEDIUM 4.3 The Schema Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing or incorrect capabilit… wordfence
dae86d7c-3bbb-4872-acd7-08ff8d437b8e MEDIUM 4.3 The WP Global Screen Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
dae01acf-3b32-46bb-9c79-bfe9abb714dd MEDIUM 4.3 The Hesabfa Accounting plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
dadb6bf5-dbbd-4afb-8783-f6880dec2cbf
< 1.0.1
MEDIUM 4.3 The Elegant Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
dac1e554-2069-4588-a570-5dacc83e4532 MEDIUM 4.3 The Multi Feed Reader plugin for WordPress is vulnerable to Cross-Site Request Forgery in version * -<=2.2.4. This is du… wordfence
dabc2ae0-6005-4287-b1b0-385bc6d5c467
< 3.4.8
MEDIUM 4.3 The WP-Members Membership for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.… wordfence
← Prev 1375 1376 1377 1378 1379 1380 1381 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top