πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1412 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b7115070-b84d-4d69-993a-f512b9f9c081
< 5.3.2
MEDIUM 4.3 The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up … wordfence
b70a57ae-4033-4e68-b806-83422d2ab68c MEDIUM 4.3 The Document Block – Upload & Embed Docs, PDF, PPT, XLS or Any Documents plugin for WordPress is vulnerable to unautho… wordfence
b7039206-a25a-4aa0-87e2-be11dd1f12eb
< 2.2.0
MEDIUM 4.3 The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized… wordfence
b6f7c4c8-210f-4bbb-8352-5c2e550e44c3
< 3.9.5
MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refe… wordfence
b6da046f-a16f-4a93-b3c6-04270538b7a9
< 5.3.1.0
MEDIUM 4.3 The RegistrationMagic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
b6d84682-6966-47fd-a04c-7f4c5b914fc6
< 2.2.4
MEDIUM 4.3 The CartFlows plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
b6c5f933-b71b-4475-abdf-4cffff2a1a6c
< 1.3.0
MEDIUM 4.3 The ARI Stream Quiz – WordPress Quizzes Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
b6bd6979-858a-446b-a8d9-d30869e73ed5
< 3.6.27
MEDIUM 4.3 The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to unauthorized a… wordfence
b6aa4ad3-a0f0-4917-acaf-2f683aecba3e
< 9.0.13
MEDIUM 4.3 The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.0.12… wordfence
b6a99d7f-f5b1-4bdc-ad67-353fea94d649
< 1.0.9.2
MEDIUM 4.3 The Transposh WordPress Translation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
b6a8dcdc-88ab-4e8e-b631-8849e10be9ba
< 5.9.5.3
MEDIUM 4.3 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Full Path Disclosure in … wordfence
b6a16d30-9f22-4b44-b748-cb0c5c32c039 MEDIUM 4.3 The WP Sticky Side Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
b6950932-e7f7-47ed-a91d-b1976cb25077
< 2.1.1
MEDIUM 4.3 The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
b68b6736-6552-4115-9702-bd178846544c
< 6.8.6
MEDIUM 4.3 The GamiPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.8.5. … wordfence
b677ad8b-4f01-4147-bcf6-ae769046be48
< 9.0.10
MEDIUM 4.3 The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.… wordfence
b649266a-6a9a-4d2e-9a82-2335e96bfe0d MEDIUM 4.3 The Hide Categories Or Products On Shop Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
b63f4de2-32e1-4c5e-a64d-fb66d2e2b3a8 MEDIUM 4.3 The Use Memcached plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0… wordfence
b623af30-9c45-47cf-998f-be6409561b62
< 1.5.0
MEDIUM 4.3 The Houzez CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
b60cb1af-c9f3-4cea-9699-d66a52eb87eb
< 2.4.1.2
MEDIUM 4.3 The DeepL Pro API translation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
b60ab23c-5dfc-4504-bb3a-98a9f891760d MEDIUM 4.3 The Reloadly plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.1. T… wordfence
b6048088-c11c-4741-8dde-da707f8f84f2
< 4.24.1
MEDIUM 4.3 The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
b6008237-e4a8-4757-ae14-ac20c6f1b0af MEDIUM 4.3 The Simple Testimonials Showcase plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
b5f8659a-fb3f-4df3-85a6-979751627a9c
< 4.9.8
MEDIUM 4.3 The WP All Import Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
b5f4e9bf-b452-4425-8bf2-73be7857b3ef
< 1.35
MEDIUM 4.3 The Sumo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.34. This i… wordfence
b5ef15c4-c96b-4e88-a941-e34d23a0e06a
< 1.6.0
MEDIUM 4.3 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
← Prev 1409 1410 1411 1412 1413 1414 1415 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top