πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1393 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cd1fc89f-b0f0-43a3-a311-07a79232a3ea
< 7.2.8
MEDIUM 4.3 The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attack… wordfence
cd132aa5-d30a-41de-aa8d-aefae6c95c47
< 4.0.3
MEDIUM 4.3 The Aurum - WordPress & WooCommerce Shopping Theme theme for WordPress is vulnerable to unauthorized modification of dat… wordfence
cd0fe8d5-ff39-44b3-91ce-8fd211fdbaea MEDIUM 4.3 The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi… wordfence
cd0abdf2-24da-4e87-825b-0796af6c3ccd MEDIUM 4.3 The Remove/hide Author, Date, Category Like Entry-Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
cd01d83e-a337-4f93-8bd0-0c9f3c786583 MEDIUM 4.3 The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could al… wordfence
ccf77cb1-b6b6-49de-8de4-20eddd3b5e62
< 8.3.7
MEDIUM 4.3 The Media Library Folders plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … wordfence
cce48da9-9c9b-49ef-bc03-371cb0e99242
< 1.1.8
MEDIUM 4.3 The Custom Login Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
ccc1dd7b-61f3-4358-bbf8-75f44200d3b1
< 1.2.5
MEDIUM 4.3 The Activity Log WinterLock plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
ccbf6d57-44ba-4064-8880-81cd9136ca33
< 4.0.8
MEDIUM 4.3 The Widget Options plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wi… wordfence
ccb34b44-9fa4-4ebe-b217-b2a42920247f
< 3.4.2
MEDIUM 4.3 The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
ccaba382-7fe8-4197-bec4-87c35d9a7a81
< 1.0.2
MEDIUM 4.3 The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
cca71257-05dc-43d5-8de6-faf0a2feab2e
< 1.4.5
MEDIUM 4.3 The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forger… wordfence
cc9dd55d-3c37-4f24-81a1-fdc8ca284566
< 3.1.14
MEDIUM 4.3 The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to … wordfence
cc9935d8-7790-457b-88bf-bee5e13b0f5a
< 5.5.6
MEDIUM 4.3 The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to unauthorized modification of data due… wordfence
cc97109c-187f-43b7-b5ed-5afeec5ea8fd MEDIUM 4.3 The Clock In Portal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
cc727156-28dc-4b0a-b777-52a1bbc72f79 MEDIUM 4.3 The AccessPress Anonymous Post plugin for WordPress is vulnerable to Arbitrary Redirect in versions up to, and including… wordfence
cc6b521b-32a4-40a2-bb4e-c0c7642693c9
< 4.0.6
MEDIUM 4.3 The Nelio Content plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
cc65d444-741d-4d27-84a8-07d916caf0e4 MEDIUM 4.3 The Pricing Table builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
cc588948-151d-4bdb-96a2-cdfde2cb0965
< 5.11.1
MEDIUM 4.3 The WP Job Board plugin for WordPress is vulnerable to Directory Traversal in all versions up to 5.11.1 (exclusive). Thi… wordfence
cc5754c2-a052-41ac-af19-7c4f55860f95
< 5.1
MEDIUM 4.3 The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all vers… wordfence
cc4ec554-f7f5-4c0a-9f86-8d5c74bfe0ab
< 2.16.2.1
MEDIUM 4.3 The Knowledge Base documentation & wiki plugin – BasePress plugin for WordPress is vulnerable to unauthorized access d… wordfence
cc490eea-455d-46f1-bbb1-d57af8ab5e74
< 2.5.4
MEDIUM 4.3 The WPGraphQL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.3. … wordfence
cc33b2fc-291a-49d5-8fe7-7bf4e9ebab5d
< 3.8.3
MEDIUM 4.3 The Mobile App Canvas – Convert your Website Into an App for iOS and Android plugin for WordPress is vulnerable to una… wordfence
cc0af0a4-81b5-425e-aba3-0c422aa33634 MEDIUM 4.3 The WP DB Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
cc03b3f4-2edb-463b-812b-6a187a7a893c
< 1.95.0.3
MEDIUM 4.3 The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
← Prev 1390 1391 1392 1393 1394 1395 1396 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top