πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1392 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ce984199-b29b-4722-8199-8e37b66e2ed9 MEDIUM 4.3 The SV Proven Expert plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
ce978334-42e1-4334-a2d1-c3966339e4fc
< 1.4.1
MEDIUM 4.3 The WordPress Backup & Migration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabi… wordfence
ce6ea115-941e-482f-a2a4-95293ff10a69
< 1.3.32
MEDIUM 4.3 The Contact Form Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
ce695f15-557c-47b1-a5c4-ce68cc84d721
< 1.3.8
MEDIUM 4.3 Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.7 allows… wordfence
ce4ac97d-7eb3-4005-b75a-0fe32e31fa92
< 2.11.1
MEDIUM 4.3 The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPr… wordfence
ce30649a-c1a0-42d5-b2e7-1ebe7989efa3
< 6.4.0
MEDIUM 4.3 The Mercado Pago payments for WooCommerce plugin is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
ce2bef2f-fe28-48ea-8b83-052eebd31622
< 1.2.6
MEDIUM 4.3 The Classic Editor and Classic Widgets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
ce1088da-8db0-4bf5-a1ee-2121d5b9840a
< 2.19.23
MEDIUM 4.3 The Spectra plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
cdfc1110-7bbd-45f0-97ef-271c45d222c1 MEDIUM 4.3 The SEATT: Simple Event Attendance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
cde526f2-7eff-49cf-8a9f-e0c0cdd12522 MEDIUM 4.3 The Kv TinyMCE Editor Add Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
cddf4aa1-5c7d-4aa1-9384-1c352f0c6da9
< 2.1.5
MEDIUM 4.3 The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized settings reset due to a missing capability check … wordfence
cddc6d2e-bf42-478a-8390-d3aa9ce04292 MEDIUM 4.3 The Add to Feedly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
cdcb09ee-80c7-445c-932f-7fce3ae743c5
< 3.4.1
MEDIUM 4.3 The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable … wordfence
cdb5a65a-313f-44b3-9a79-7fae1207e8e2
< 3.3.1
MEDIUM 4.3 The Bridge Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
cd9d7d34-c03d-4791-94b4-9d2f502a7e37 MEDIUM 4.3 The eDoc Easy Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
cd95f517-baf6-4feb-a9a5-f73008634dd4
< 1.0.23
MEDIUM 4.3 The WP Client Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
cd9490f2-ad52-477e-ae3b-be49984e8189
< 0.4.8
MEDIUM 4.3 The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
cd726b20-75c9-408e-86fc-061db591a9db
< 1.5.3
MEDIUM 4.3 The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t… wordfence
cd679d7b-d8d9-46c4-87d2-8d04506ee5dd MEDIUM 4.3 The Simple Keyword to Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
cd5e9736-e4d9-4730-aaaf-2069a9633f02
< 1.0.8
MEDIUM 4.3 The NewsXpress theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.7. … wordfence
cd49bf11-825d-4e63-8522-f765c5d79f57 MEDIUM 4.3 The Total Poll Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
cd493279-215e-422c-a9f9-353032b8d4aa
< 3.1.4
MEDIUM 4.3 The JS Help Desk plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, … wordfence
cd47f21c-70e1-4458-a552-377956141a65
< 1.3.6
MEDIUM 4.3 The Transcoder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.5.… wordfence
cd3fb4fc-6a15-4b8e-8a0b-048a377fda67 MEDIUM 4.3 The Popularis Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
cd2c9b28-d5b5-4930-a441-f889ee2778cd
< 5.0.5
MEDIUM 4.3 The SchedulePress – Best Editorial Calendar, Missed Schedule & Auto Social Share plugin for WordPress is vulnerable to… wordfence
← Prev 1389 1390 1391 1392 1393 1394 1395 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top