πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1391 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cfa8aaf8-10c8-4024-8223-6218963012d2
< 2.6.12
MEDIUM 4.3 The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPres… wordfence
cf806412-9f21-468e-a497-319d5b24e677
< 3.5.2.7
MEDIUM 4.3 The Tickera plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the g… wordfence
cf7ec469-70b7-4ec2-83df-c788c76730b4
< 1.3.2
MEDIUM 4.3 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… wordfence
cf7bdd0e-f3b3-4be5-8a30-2c6d9cb783a3
< 3.2.4
MEDIUM 4.3 Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capabili… wordfence
cf71d36c-c730-470b-bd22-a393370d867c
< 1.33.21
MEDIUM 4.3 The WebinarPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.33… wordfence
cf6e5800-9885-4258-87a5-0e0de75f955d
< 5.25.10
MEDIUM 4.3 The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
cf5075f9-9658-4a09-bd38-34a72f6560f4
< 4.1.7
MEDIUM 4.3 The Starter Templates β€” Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-S… wordfence
cf47c784-c232-4cec-8dd4-8f7d3987c6ee
< 1.9.7
MEDIUM 4.3 The Arconix FAQ plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
cf433ec6-7f75-4608-81b3-ea24078b6b6c MEDIUM 4.3 The ONet Regenerate Thumbnails plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
cf3d2b0f-667f-469e-a1de-3be213cd7007
< 1.0.3
MEDIUM 4.3 The TrueBooker – Appointment Booking and Scheduler Plugin. plugin for WordPress is vulnerable to Cross-Site Request Fo… wordfence
cf34af9d-4de7-498d-8065-c3cc6818b7c4
< 3.0.7
MEDIUM 4.3 The Advance Menu Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
cf2e8b6f-2bdb-46c4-84a0-9e196355dda9
< 2.0
MEDIUM 4.3 The No-Bot Registration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
cf2c451d-a30c-4c0f-9cf0-6361f6b1913c
< 3.4.7
MEDIUM 4.3 The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Obj… wordfence
cf229083-ac10-42c0-a70a-f273e3eab1ce
< 2.7.2
MEDIUM 4.3 The EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin plugin for WordPress is vulnerable to … wordfence
cf13732b-7c24-443a-bae9-d8cf70b5cb33
< 2.4.0
MEDIUM 4.3 The Stock Sync for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
cefa38d0-7da1-48dd-98d7-fe2f36e19d7c
< 1.6.5
MEDIUM 4.3 The WooCommerce Order Barcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
ced4a635-f579-41fb-840c-3ba54dbe92c8 MEDIUM 4.3 The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status … wordfence
ced380a5-04a6-40c1-a731-0d3b929e4428
< 1.2.0
MEDIUM 4.3 The CP Media Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
cecebfd0-c2af-4150-8793-299cdbeaa7b9
< 1.3.4
MEDIUM 4.3 The Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) plugin for WordPress i… wordfence
cec0ba0e-28a5-46c0-97c2-bbf73bd2dbad
< 2.211
MEDIUM 4.3 The Bard theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.210. This i… wordfence
ceb7117a-d8b3-44bb-a1f0-3f585135c895
< 3.9.13
MEDIUM 4.3 The Tutor LMS plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin… wordfence
ceb3ec6d-9960-441c-82ca-3cba9da77495
< 2.7.8.5
MEDIUM 4.3 The Participants Database plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
ceaccdb3-4d98-4463-9db9-a6f1712d6869 MEDIUM 4.3 The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up t… wordfence
ce9f1611-46ce-4eb7-927c-1cc097f03bd9 MEDIUM 4.3 The Hacklog Remote Attachment plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
ce9dab37-4118-4e13-857c-9aa072d25edf
< 2.17.4
MEDIUM 4.3 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… wordfence
← Prev 1388 1389 1390 1391 1392 1393 1394 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top