πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1390 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2026-2518 MEDIUM 4.3 The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing ca… nvd
CVE-2026-2301 MEDIUM 4.3 The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all ve… nvd
CVE-2026-2230 MEDIUM 4.3 The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i… nvd
CVE-2026-2112 MEDIUM 4.3 The Dam Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… nvd
CVE-2026-2023 MEDIUM 4.3 The WP Plugin Info Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… nvd
CVE-2026-1860 MEDIUM 4.3 The Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi… nvd
CVE-2026-1857 MEDIUM 4.3 The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers… nvd
CVE-2026-1655 MEDIUM 4.3 The EventPrime plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization checks … nvd
CVE-2026-1455 MEDIUM 4.3 The Whatsiplus Scheduled Notification for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery i… nvd
CVE-2025-14864 MEDIUM 4.3 The Virusdie - One-click website security plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… nvd
CVE-2025-14742 MEDIUM 4.3 The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … nvd
CVE-2025-14342 MEDIUM 4.3 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … nvd
CVE-2025-14167 MEDIUM 4.3 The Remove Post Type Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… nvd
CVE-2025-13413 MEDIUM 4.3 The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … nvd
CVE-2025-13091 MEDIUM 4.3 The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … nvd
CVE-2025-12172 MEDIUM 4.3 The Mailchimp List Subscribe Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… nvd
CVE-2025-12081 MEDIUM 4.3 The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… nvd
CVE-2025-12075 MEDIUM 4.3 The Order Splitter for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca… nvd
CVE-2025-12071 MEDIUM 4.3 The Frontend User Notes plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an… nvd
CVE-2025-12027 MEDIUM 4.3 The Mesmerize Companion plugin for WordPress is vulnerable to unauthorized access and modification of data due to a miss… nvd
cffb3b61-fefc-4bf8-9904-55a7143aeef1
< 5.3.0.1
MEDIUM 4.3 The Uncanny Automator Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 5.3.0.1. Th… wordfence
cfd69b54-3056-4909-b3e8-ef2387ea9ea8
< 1.4.2.1
MEDIUM 4.3 The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to unauthorized modification of data due … wordfence
cfb87c87-f9dc-4f26-93f5-10d6bf6c822b
< 2.5.2
MEDIUM 4.3 The WP Discourse plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
cfb45af3-c22a-4045-b564-22f7081868d7
< 2.1.7
MEDIUM 4.3 The WP Mail Catcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
cfaea9dd-98bf-4835-9c9f-362bf01e4639 MEDIUM 4.3 The Infusionsoft Analytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
← Prev 1387 1388 1389 1390 1391 1392 1393 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top