πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1405 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bfa7ae6c-6bc8-4787-b95b-c12243d0a45c
< 1.4.26
MEDIUM 4.3 The Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini plugin for WordPress is vulnerable to unauthorized ac… wordfence
bf801042-5cd5-424f-a25a-858302285170
< 1.24.2
MEDIUM 4.3 The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Cross-Site R… wordfence
bf798142-4daf-41f5-8416-701d03476520
< 2.0.12
MEDIUM 4.3 The WooCommerce Conversion Tracking plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
bf77908d-2469-449b-abab-f8411ee42f65
< 4.6.0
MEDIUM 4.3 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized acces… wordfence
bf539c01-596a-44dd-9587-6be6978ab0fa
< 2.28.15
MEDIUM 4.3 The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … wordfence
bf51e9ef-7a4b-4f5b-82ae-0de6bcd90758
< 2.0.23
MEDIUM 4.3 The Market Exporter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
bf2ddc42-9910-40e5-9546-89f229b852da MEDIUM 4.3 The Category Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2… wordfence
bf1f402d-98d7-42d7-8d8d-ff74a65e5293 MEDIUM 4.3 The Permalinks Customizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
bf0ad697-159f-4466-aa7e-d7c60b737cd8
< 0.6
MEDIUM 4.3 The HD Quiz – Save Results Light plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
bf0871e7-7dc4-4acb-868f-7dc32016582e MEDIUM 4.3 The Goldstar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
bf05a79a-0375-4c9d-bbf0-a87484327b87
< 3.4.8
MEDIUM 4.3 The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing cap… wordfence
becbf49b-0384-4c78-a983-2effbfac8dd1 MEDIUM 4.3 The WP Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
bec89b35-8cf2-4afa-8f3e-92ee6420ae28
< 1.2.21
MEDIUM 4.3 The Elastic Email Sender plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
bec19d80-ba51-4ff8-a111-c2e45928fb51
< 2.0.12
MEDIUM 4.3 The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and … wordfence
beadd35b-2bce-431e-8347-2d1a87d02f01 MEDIUM 4.3 The Users To CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.… wordfence
bea4b2c6-f078-4b47-b4d3-16216a54c0ab
< 1.9.3
MEDIUM 4.3 The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
be9811b8-602f-4525-bc15-75e5efe794f6
< 2.3.2
MEDIUM 4.3 The Fluent Support Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
be964722-2080-4289-a960-a460a8d09c9e
< 1.4.3
MEDIUM 4.3 The News Kit Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
be8ec147-1469-449b-b51b-f1c328b1922f MEDIUM 4.3 The User Activity Log Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
be8dcff9-1626-4919-b297-c423891f3d02 MEDIUM 4.3 The Simple Mobile URL Redirect plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
be86c751-499b-4772-a457-14427fa56c39 MEDIUM 4.3 The Ray Enterprise Translation plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
be837a77-9b25-43af-aaba-94a8aa59e7e3
< 4.6.15
MEDIUM 4.3 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized access of data due … wordfence
be73e45a-ce00-4a1f-b722-32a94c5beadc
< 1.2.11
MEDIUM 4.3 The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks on the … wordfence
be436047-6bea-465b-8de1-b0a081a85ed6 MEDIUM 4.3 The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… wordfence
be3869a9-f72d-4bbb-ba51-d2761ca761f2
< 1.1.0
MEDIUM 4.3 The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a… wordfence
← Prev 1402 1403 1404 1405 1406 1407 1408 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top