πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1404 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c09b634f-1d36-4454-8e2a-f12d7711d64f
< 2.2.0
MEDIUM 4.3 The WP Job Manager - Resume Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
c0979a15-5fa9-4024-81a8-3555d6f73e61
< 4.0.7
MEDIUM 4.3 The MainWP Comments Extension plugin for WordPress is vulnerable to authorization bypass due to a missing capability che… wordfence
c0915660-fcc9-451f-a6bc-60b6fd86ec63
< 2.1.5
MEDIUM 4.3 The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
c08d420d-d521-4215-9ef7-b5d1c44a19d3 MEDIUM 4.3 The Permalinks Cascade plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,… wordfence
c083992b-a0dd-4709-b152-08f5b7ca55dc MEDIUM 4.3 The illow – Cookies Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
c06f21f7-3552-4de2-89e7-ed331f61235d
< 1.6.8
MEDIUM 4.3 The Media Library File Size plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
c0538999-0a09-4d24-a530-a32fb5b4e5e6
< 6.4.7.2
MEDIUM 4.3 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
c045b31f-b4d6-470e-8f93-36eb70bb75f8
< 1.1.4
MEDIUM 4.3 The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du… wordfence
c04449a1-24ac-4dca-932b-fc8c62b53ce6 MEDIUM 4.3 The TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Bui… wordfence
c043510b-6aeb-4e91-80f0-a62970c01b1d
< 2.8.29
MEDIUM 4.3 The Sunshine Photo Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
c03b5670-9f7e-4001-ba90-197559b794a1
< 1.1.11
MEDIUM 4.3 The UserHeat Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
c03a3604-3bd5-4bd8-9294-92a8f9fcdd5e
< 2.4.4
MEDIUM 4.3 The ClickWhale plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3.… wordfence
c039d2fe-7518-4724-a025-6380a53fb58c
< 5.8.4
MEDIUM 4.3 The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorize… wordfence
c02c824a-dc6e-4329-8e1b-0519b6c4e4c0
< 3.6.4
MEDIUM 4.3 The WordPress REST API Authentication plugin for WordPress is vulnerable to unauthorized modification of data that can l… wordfence
c025e94e-023e-41d5-a2c2-18c9940af8b8
< 1.5.3
MEDIUM 4.3 The Zapier for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
c01e3a86-8a2a-4200-b328-fb71afb2b196
< 5.8.0
MEDIUM 4.3 The WooCommerce Subscriptions plugin for WordPress is vulnerable to unauthorized access of data or modification of data … wordfence
c00d83a7-dd7a-407d-b44e-7ee0a2a1492a MEDIUM 4.3 The Elementor Addons AI Addons – 70 Widgets, Premium Templates, Ultimate Elements plugin for WordPress is vulnerable t… wordfence
bfffed4d-dacb-4591-840c-45105a58362a
< 7.11.2
MEDIUM 4.3 The Avada theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an… wordfence
bff60dda-30e2-4660-931e-4bb9acae0396
< 4.0
MEDIUM 4.3 The BSK Forms Blacklist plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
bfef57b6-26b1-433b-9037-46f908422f72 MEDIUM 4.3 The Book a Room plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
bfd92ce0-1017-488c-9418-1e739868c4d5
< 9.2
MEDIUM 4.3 The SEOPress PRO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
bfd59e66-d9f2-4e45-af90-e78950860f96 MEDIUM 4.3 The Piotnet Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0… wordfence
bfcd914c-3c12-4e6a-bb05-38d42ce411d4
< 2.0.2
MEDIUM 4.3 The 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On plugin for WordPress is vulnerable to authori… wordfence
bfb77432-e58d-466e-a366-8b8d7f1b6982
< 6.1.8
MEDIUM 4.3 The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access du… wordfence
bfa8328b-5932-4396-b0ef-e16a7ec3b365
< 2.0.5
MEDIUM 4.3 The Exit Popups & Onsite Retargeting by OptiMonk plugin for WordPress is vulnerable to Cross-Site Request Forgery in ver… wordfence
← Prev 1401 1402 1403 1404 1405 1406 1407 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top