πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1409 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ba998993-4e89-45f8-9598-fc1f8b88d147
< 1.4.4
MEDIUM 4.3 The Insert PHP Code Snippet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
ba8de7af-6167-4aa8-8222-481b04e6fcb2
< 3.14.4
MEDIUM 4.3 The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
ba86268a-7bd6-40ed-9af6-29409245675d
< 19.10.0
MEDIUM 4.3 The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized modification of… wordfence
ba619587-21d2-48b2-984a-210b43b0d87b MEDIUM 4.3 The Simple Trackback Disabler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
ba5cca24-514b-4f8b-911f-8d138287fce2
< 3.2.12
MEDIUM 4.3 The Robo Gallery Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.… wordfence
ba3d59a1-d0f6-4fe8-bf79-35b35b2a2fee
< 1.1.5
MEDIUM 4.3 The ShipTime: Discount Shipping plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up … wordfence
ba351515-d984-42da-9530-5e7afad3df29 MEDIUM 4.3 The Fast User Switching plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
ba2ff1ab-f981-417d-b400-13750c9320ad
< 1.7.4
MEDIUM 4.3 The WP Social Comments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… wordfence
ba27d52e-e43a-4f03-ad99-632c18279413
< 1.90
MEDIUM 4.3 The WP-PostRatings plugin for WordPress is vulnerable to Race Condition in versions up to, and including, 1.89. This can… wordfence
ba22205d-5c09-4901-ba8b-0ffe2f4a09e0
< 4.8.7.2
MEDIUM 4.3 The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable t… wordfence
ba20a30c-7dd2-4cb7-b055-9a105461f7d1
< 2.4.4
MEDIUM 4.3 The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX a… wordfence
ba111255-3b91-4ef6-8d57-10ff08363c48
< 5.1.10
MEDIUM 4.3 The Download Monitor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1… wordfence
b9edcbdc-5b01-4880-95ec-57d87ccbb472
< 2.0.1
MEDIUM 4.3 The VG WORT METIS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
b9e25fd7-848d-4d33-9c49-72f4698856e2 MEDIUM 4.3 The Ave Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
b9d63462-04ec-4b46-91cf-25b7dd098fc7
< 2.1.6
MEDIUM 4.3 The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete co… wordfence
b9d161a3-eb9f-447f-b2d2-b8b193678d20
< 1.22
MEDIUM 4.3 The First Order Discount Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
b9b92a1f-19d5-4aaa-b196-043f26e4614f
< 1.1.4
MEDIUM 4.3 The Acknowledgify plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
b9b18739-67ed-4cb0-9577-eb60bc84bbeb
< 2.5.7
MEDIUM 4.3 The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
b9a4e0c1-7bbb-4ab0-948c-3d172717e5fe MEDIUM 4.3 The Chat by Chatwee plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
b99ba627-1d24-4be1-a4db-ff39354526f2 MEDIUM 4.3 The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
b9982ccd-e9b3-46e3-90ed-1ae6ff59bb62 MEDIUM 4.3 The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
b98c5623-15fe-4937-9a0e-770aa0ab06f3
< 2.3.3
MEDIUM 4.3 The Hide admin notices – Admin Notification Center plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
b9842421-93da-4535-9d48-fd591cd5e80f
< 1.2.151
MEDIUM 4.3 The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to unauthoriz… wordfence
b9815a47-dc71-4dd0-8645-f52408ecb20f
< 3.6.0
MEDIUM 4.3 The DoFollow Case by Case plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
b97b84a8-cf4e-4648-8d58-b81a71b7988c
< 0.6.2.5
MEDIUM 4.3 The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to a missin… wordfence
← Prev 1406 1407 1408 1409 1410 1411 1412 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top