πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1407 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bcde21fd-8a2b-482d-91a0-7c8578055b61
< 2.4.6
MEDIUM 4.3 The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnera… wordfence
bcdc73d4-f47d-4bbf-a47c-1028021fb5a4
< 1.8.5
MEDIUM 4.3 The CM Pop-Up – Create engaging popups to capture attention and boost interaction plugin for WordPress is vulnerable t… wordfence
bcd6a860-3f60-474c-a5bf-e0ed4ca574be MEDIUM 4.3 The Base64 Encoder/Decoder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
bcd5b83a-7d51-455b-bb31-dd776264fc6b MEDIUM 4.3 The Skysa Text Ticker App plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
bcc7f142-b330-492f-9855-10b443a98b63
< 3.24.1
MEDIUM 4.3 The FlexTable – Data Table Sync with Google Sheets plugin for WordPress is vulnerable to unauthorized access due to a … wordfence
bca37dc1-64a7-4265-bd38-d58844140336
< 4.6.0
MEDIUM 4.3 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Sensitive Informat… wordfence
bc9a2639-cec8-408e-9ba2-ffb6c8c7da21
< 1.0.44
MEDIUM 4.3 The Google Maps CP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
bc96bbc5-b4ad-4076-a0dd-13e3407b9d76
< 7.7.4
MEDIUM 4.3 The ChatBot plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
bc883e7e-af82-47e1-a0c0-122e6abd6b52
< 2.1.7
MEDIUM 4.3 The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… wordfence
bc6cfad1-d23a-4a96-9d6c-841b6d795a01
< 7.13.55
MEDIUM 4.3 The Super Socializer plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce checks on sev… wordfence
bc5ef2cf-8b97-4aca-8e90-bb0a19788e4e
< 1.9.2
MEDIUM 4.3 The Stripe Payments For WooCommerce by Checkout plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers… wordfence
bc5da189-838d-4c0b-a734-283c4da36473
< 3.1.2
MEDIUM 4.3 The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to unauthorized loss of data due to a missin… wordfence
bc59b997-a8e2-4c75-aa5f-36cc5a66326e MEDIUM 4.3 The Plainview Protect Passwords plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
bc44c95e-9ca0-46d0-8315-72612ef3f855
< 1.2.0
MEDIUM 4.3 The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of… wordfence
bc3f1d4e-84f7-4878-8b06-10444caa7dcf MEDIUM 4.3 The WP iCal Availability plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
bc2cbf43-3e8a-4364-9355-6d6587204c1c
< 1.1.8
MEDIUM 4.3 The MSHOP MY SITE plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
bc2af96c-09c5-4ddf-a910-04291aeeef49
< 2.0.4
MEDIUM 4.3 The Ultimate Member plugin for WordPress is vulnerable to unrestricted file uploads in versions prior to version 2.0.4. … wordfence
bc20f303-cac3-4517-9c45-153c410a13af
< 1.1.4
MEDIUM 4.3 The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to … wordfence
bc200f72-072d-407d-9114-201241c244f2 MEDIUM 4.3 The Questionar for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
bc1dfd50-aeac-465a-a402-ba85c50fdfc5
< 7.0.1
MEDIUM 4.3 The PlatiOnline Payments plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
bc1abdd7-d563-44af-86d3-58005706d624
< 4.4.3
MEDIUM 4.3 The WPC Grouped Product for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
bbe973a3-a8bf-4037-9067-7cc0987291fe
< 3.0.2
MEDIUM 4.3 The qTranslate X Cleanup and WPML Import plugin for WordPress is vulnerable to unauthorized modification of data due to … wordfence
bbdeaa77-72c9-4afc-8913-7a1e44cdeb82 MEDIUM 4.3 The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
bbd0fb22-a39c-43f5-a93c-976b7e49967b
< 1.34.0
MEDIUM 4.3 The YITH WooCommerce Account Funds Premium plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
bbcdb70f-77db-48ab-ae23-c46caecdd3be
< 3.8.15
MEDIUM 4.3 The Ultimate Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
← Prev 1404 1405 1406 1407 1408 1409 1410 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top