ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1411 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b81b06b4-559f-4b69-9fdd-e09e66525867
< 2.5.10
MEDIUM 4.3 The Wallet System for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
b80c8888-e8d6-4458-ae93-8e4182060590
< 4.53
MEDIUM 4.3 The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is v… wordfence
b80b7152-be95-4737-b324-be0a3ff7c354
< 2.8.168
MEDIUM 4.3 The GeoDirectory plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, … wordfence
b7fb851b-dcf0-4074-82f3-dd2e57429a70 MEDIUM 4.3 The Freshchat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.4. … wordfence
b7e417c2-bf9c-4c88-be2b-9c2324897b07
< 1.4.2
MEDIUM 4.3 The Laposta Signup Basic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
b7db3d45-2b96-4ba4-b258-08ee5e0b947b
< 2.0.0
MEDIUM 4.3 The Pro Mime Types plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
b7c54b5d-ad73-44f1-afdb-01136ec0b9ae
< 1.0.1
MEDIUM 4.3 The Web to SugarCRM Lead plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
b7c39952-d179-4b40-9762-7815e881a560
< 5.7
MEDIUM 4.3 The Dynamic Word Spinner: CSS3 Animated Rotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
b79e0723-9e6f-44e9-ba85-393cea134f94 MEDIUM 4.3 The Ð¯Ð½Ð´ÐµÐºÑ Ð”Ð¾Ñтавка (Boxberry) plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
b798cd27-03c3-495e-aa94-743d80a493e0
< 3.5.6.3
MEDIUM 4.3 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
b797e141-a9d2-48c4-a44e-a59a80a90a5b
< 2.9.4.1
MEDIUM 4.3 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all version… wordfence
b796b514-b6ca-4a22-9340-df02fec97075 MEDIUM 4.3 The WP Custom Post Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
b793a4cb-3130-428e-9b61-8ce29fcdaf70
< 1.1.3
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
b77b0802-2efe-45d1-b338-d6d020f2bb05 MEDIUM 4.3 The WP-PManager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
b764f232-6638-4866-b48c-1f89efac76c6 MEDIUM 4.3 The Login Alert plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0… wordfence
b758c8a7-6220-4b54-af88-7933a530b5ba
< 1.3.0
MEDIUM 4.3 The ARI Stream Quiz – WordPress Quizzes Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
b75789ff-6050-4044-a3ff-d071591b4ec6
< 4.0.0
MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access due to … wordfence
b75696a4-fc07-4ab4-b108-6425c050de50 MEDIUM 4.3 The Interactive UK Regional Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
b74c99e7-e7e4-4bb6-a1e5-3ff7047400cd MEDIUM 4.3 The WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek plugin for WordPre… wordfence
b74a5a4c-250a-46bc-bf08-2dd720de41ae
< 1.2.3
MEDIUM 4.3 The Contact Form 7 Connector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
b73ca36d-c6cc-482d-a9b8-dd76327aef08
< 1.9.2
MEDIUM 4.3 The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to … wordfence
b738a4fe-6724-4216-be77-ea67843f89d1
< 5.3.7
MEDIUM 4.3 The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPre… wordfence
b73467de-fb0c-45e3-b3ae-5158b261907b
< 2.3.9
MEDIUM 4.3 The Button Generator – easily Button Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… wordfence
b71958cc-6438-4a0c-af49-f1fd4932ad24
< 4.4.0
MEDIUM 4.3 The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to unau… wordfence
b712250f-4315-4188-bbe1-c2991a10ad3f
< 3.0.1
MEDIUM 4.3 The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
← Prev 1408 1409 1410 1411 1412 1413 1414 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top