πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1394 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cc0087a8-ec3a-4c16-8ce3-d346ae0ca58d
< 8.2.1
MEDIUM 4.3 The WP Customer Area plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… wordfence
cbff7ec1-535d-43bf-be61-83a1e7625c77
< 3.2.5
MEDIUM 4.3 The Top 10 – Popular posts plugin for WordPress is vulnerable to insufficient access control in the 'tptn_chart_data' … wordfence
cbfd8d72-ce1a-4366-9d1b-13c8c5fe8b71
< 1.0.253
MEDIUM 4.3 The Rank Math SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the tra… wordfence
cbe7a209-d5c8-4616-bdcb-c52569231774
< 2.8.4.4
MEDIUM 4.3 The WP Mobile Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
cbdfe58e-1e09-41b6-8ac9-6976c27aa58d
< 3.2.17
MEDIUM 4.3 The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and i… wordfence
cbcf3487-c1d4-4173-b197-1dd381990eb7 MEDIUM 4.3 The WP Emoji One plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.… wordfence
cbc05086-e7ba-4139-a294-52a19ffc8b93
< 3.3.202
MEDIUM 4.3 The Zephyr Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
cbbf9fbb-74fd-42eb-a781-2a720fe56b13
< 6.20.02
MEDIUM 4.3 The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up t… wordfence
cbba781f-c710-4360-a4ed-21a8f7350bb9 MEDIUM 4.3 The Database to Excel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
cbb8501e-7e8b-4ed6-8792-c685a69de982
< 5.0.6
MEDIUM 4.3 The Slimstat Analytics plugin for WordPress is vulnerable to unauthorized PageView Deletion due to a missing capability … wordfence
cbb5e80a-4dfe-429c-96c1-7fab52e0ce21
< 1.4.3
MEDIUM 4.3 The Contact Form Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
cbb0f6cf-c41d-4e54-addd-3f2454d02152
< 4.23.0
MEDIUM 4.3 The KALLYAS - Creative eCommerce Multi-Purpose WordPress Theme theme for WordPress is vulnerable to unauthorized access … wordfence
cbaf06b2-9ac3-4882-9212-fdcecdc5fb8c
< 3.99
MEDIUM 4.3 The Memory Usage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
cb879587-6210-4e23-8f02-9ce93a271962
< 4.24.16
MEDIUM 4.3 The Flexible Shipping plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
cb7ec7ad-797b-4a5c-9b1c-31284083faef
< 2.25.2
MEDIUM 4.3 The GiveWP plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.1. This is due to m… wordfence
cb5cb1a5-30d2-434f-90f9-d37aecfbe158
< 3.9.7
MEDIUM 4.3 The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the m… wordfence
cb427792-8675-4c38-a4e6-ba2b8091003f
< 4.2.3
MEDIUM 4.3 The TinyMCE Advanced plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
cb3d8d70-a965-4ef7-9b03-f64cb0fdbf8f MEDIUM 4.3 The Zajax – Ajax Navigation plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
cb3157b3-0ba1-4471-a3d7-bab65c68a611
< 8.4.2
MEDIUM 4.3 The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress … wordfence
cb18d6d8-28e5-4125-9209-a71403f678f0
< 1.0.2
MEDIUM 4.3 The Form Block plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1.… wordfence
caff9be6-4161-47a0-ba47-6c8fc0c4ab40
< 2.6.0
MEDIUM 4.3 The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Refe… wordfence
caf61bf9-4b0f-450a-b571-b0fec42e9e39
< 1.2.7
MEDIUM 4.3 The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, whic… wordfence
cad19306-6eef-4f80-9442-e7b314b3a873 MEDIUM 4.3 The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
cacd9237-a330-4927-ac53-ee86b9ac8289
< 4.7.10
MEDIUM 4.3 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
cac1c1fa-7d6c-43c3-885e-9be320cb8f83
< 4.7.34
MEDIUM 4.3 WordPress Core is vulnerable to an Email Change Confirmation Bypass in all versions up to, and including, 7.0.2 due to i… wordfence
← Prev 1391 1392 1393 1394 1395 1396 1397 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top