πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1406 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
be30e951-7c8d-4baf-9288-0d12dacc0dc2
< 1.2.3
MEDIUM 4.3 The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization b… wordfence
be23388e-9371-4ea0-974b-80f76de90012
< 1.7.0
MEDIUM 4.3 The Split Test For Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
be071489-8de4-4a27-8d90-f41a86e02683
< 1.69.234
MEDIUM 4.3 The WP Fast Total Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
bdf534bc-43a9-4f1b-9705-b367fbf870ac
< 2.21.13.1
MEDIUM 4.3 The Seraphinite Accelerator Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
bde75c5a-b0b7-4f26-91e9-dd4816e276c9
< 1.0.1
MEDIUM 4.3 The Thumbnail carousel slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is d… wordfence
bdd3868a-d741-42b4-bc7f-6fb5d33bb71b
< 2.5.3
MEDIUM 4.3 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|lo… wordfence
bdbb9f2b-dbfa-4f6a-b7df-97e47683a80e
< 1.2.14
MEDIUM 4.3 The Product Bundles, Quantity/Bulk Discount, BOGO, Buy X Get Y – WowRevenue plugin for WordPress is vulnerable to unau… wordfence
bdbb660b-19aa-4c68-865c-0a51b85d1e5a
< 1.3.6
MEDIUM 4.3 The SocialChamp with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
bdba8dee-f831-4316-a18e-d177762a7df4 MEDIUM 4.3 The Image Cleanup plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
bdb40f51-dac2-40e7-beb1-154d982f7af3 MEDIUM 4.3 The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and inclu… wordfence
bda44801-6599-459d-a70c-164f563bf158
< 3.8.6
MEDIUM 4.3 The WooCommerce Ship to Multiple Addresses plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
bda326b0-9049-496a-a600-fa65151ce98f
< 2.6.3
MEDIUM 4.3 The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for W… wordfence
bd9f4105-0300-4031-9755-349939184735 MEDIUM 4.3 The SCSS-Library plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
bd9b6575-f49b-4586-a716-69d39242423d
< 1.0.39
MEDIUM 4.3 The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all … wordfence
bd91f58e-8804-4b66-861b-525f4dd9436d
< 3.1
MEDIUM 4.3 The CSS3 Accordions for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
bd788e9c-223c-432f-9369-d9af380324e9 MEDIUM 4.3 The Zalo Official Live Chat plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
bd5d212e-c672-4fa8-afe7-baeac06e2e7d
< 2.12.9
MEDIUM 4.3 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulner… wordfence
bd49d77c-d552-47ae-b680-4ab0e4a8a906
< 3.4.10
MEDIUM 4.3 The Print Barcode Labels for your WooCommerce products/orders plugin for WordPress is vulnerable to unauthorized access … wordfence
bd34f257-d373-424e-830a-fe3cc56447f7
< 1.6.7
MEDIUM 4.3 The Spider Elements – Crafted UX First Addons for Elementor plugin for WordPress is vulnerable to unauthorized access … wordfence
bd240932-ad50-40b3-94c7-6e885f96c5df MEDIUM 4.3 The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.9.91.… wordfence
bd191d42-f41b-45c3-81b6-3d4eeea0f3fa
< 8.7.3
MEDIUM 4.3 The WPBakery Page Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
bd004e84-88e5-4eb5-903f-0fe20ddd395e
< 5.0.8
MEDIUM 4.3 The Spiffy Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
bcfb8a13-1320-4187-ba4c-887c66f0fc1e MEDIUM 4.3 The Hotel Listing plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
bcf7c4ad-7d8a-491c-b401-8b02af4a21c3
< 3.8.1
MEDIUM 4.3 The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie C… wordfence
bce54eb6-1c41-4922-a9b2-a7b77cda29b3
< 3.21.2
MEDIUM 4.3 The Ultimate Addons for WPBakery Page Builder plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
← Prev 1403 1404 1405 1406 1407 1408 1409 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top