πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1408 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bbc8e925-878a-42e2-ae78-35ec95e07526
< 3.4.5
MEDIUM 4.3 Cross-Site Request Forgery (CSRF) vulnerability leading to plugin Settings Update discovered in WP Content Copy Protecti… wordfence
bbc60271-5f22-48fe-8f56-a66549daf638
< 1.18.9
MEDIUM 4.3 The Pochipp plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
bbc41888-35e5-483b-b048-7a504d2e5566
< 5.6.3
MEDIUM 4.3 The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.2. … wordfence
bbb40038-75ea-4f09-b852-d90b087f1802 MEDIUM 4.3 The sourceplay-navermap plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
bbb19be3-8783-4474-a258-285e3b90f1e0
< 1.0.13
MEDIUM 4.3 The Meks Video Importer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
bba5f363-8d75-4c73-b8ae-eccf06dd1979
< 1.5
MEDIUM 4.3 The PDF Thumbnail Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
bb995311-8837-4db5-a25d-37e41d932774
< 5.25
MEDIUM 4.3 The WP Tools Repair, Javascript errors, Jquery errors, Increase Maximum Limits, File Permissions, Transients, Error Log … wordfence
bb8aca3a-e4f7-41d6-9ea9-d189817c2c04
< 2.3.5
MEDIUM 4.3 The Visibility Logic for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
bb81b2ce-583b-411c-b0f5-a233e0d1986b
< 1.2.2
MEDIUM 4.3 The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
bb7d99a7-1e7d-43e1-839c-286b454c8276 MEDIUM 4.3 The SendGrid for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability c… wordfence
bb70ad52-b964-4c56-98a2-06be375a79af MEDIUM 4.3 The AdminQuickbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
bb671c8f-9e14-4f79-adfa-72f48ec02449
< 3.0.12
MEDIUM 4.3 The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0… wordfence
bb53b541-1c7a-4265-ba7a-18be976a01d7
< 1.3.58
MEDIUM 4.3 The Findgo - Directory Listing WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all ve… wordfence
bb280004-e0ba-44c8-a205-8fec30900d86
< 8.0.1398
MEDIUM 4.3 The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPres… wordfence
bb1fe70b-80f8-408f-8f4b-4eca57c6ade8
< 1.7.1
MEDIUM 4.3 The WP Sync for Notion – Notion to WordPress plugin for WordPress is vulnerable to unauthorized access due to a missin… wordfence
bb175149-05b5-4e8e-8437-9a07762c7269
< 3.12.28
MEDIUM 4.3 The Easy Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and excl… wordfence
bb15316c-2414-40c0-97e7-0b4d1b8293a4 MEDIUM 4.3 The gap-hub-user-role plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
bb0f8a0c-d02f-46e2-8808-3ffada105d13
< 3.5.1.1
MEDIUM 4.3 The Tickera plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.1.0. … wordfence
baf2af6b-277e-4613-b066-1f2acda56602
< 5.0.1
MEDIUM 4.3 The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Content Inje… wordfence
baee1bba-c531-4a6a-8e4d-5c44e3d7e84f
< 5.2.6
MEDIUM 4.3 The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all… wordfence
bae67a68-4bd1-4b52-b3dd-af0eef014028
< 1.1.3
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check … wordfence
bae36712-f400-4965-9885-de9f7fbfd9b1 MEDIUM 4.3 The Just TinyMCE Custom Styles plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
bad0bd6b-9c88-4d31-90b5-92d3ceb8c0af
< 0.9.95
MEDIUM 4.3 The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the r… wordfence
bab68830-5ac5-4aa3-929a-ba2bca03b1ca MEDIUM 4.3 The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0… wordfence
baa8e48f-769a-4f48-bc47-d55c179d1ca1
< 3.1.15
MEDIUM 4.3 The Post to Google My Business plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
← Prev 1405 1406 1407 1408 1409 1410 1411 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top