πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1414 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b4a44a8a-740b-45dd-962c-945238f6ddee
< 1.4.3
MEDIUM 4.3 The PayPal Brasil para WooCommerce Plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
b49bb71b-1cdd-4341-9288-d33c74bc9426 MEDIUM 4.3 The Free Woocommerce Product Table View – Woo Table Pro plugin for WordPress is vulnerable to unauthorized access due … wordfence
b492ccac-9cdc-42e1-9f0b-4612622d4266
< 2.1.7
MEDIUM 4.3 The Goodlayers Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 2.1.7 (exclusive). … wordfence
b48bc632-c825-48e0-8766-3ac59e5b87c6
< 3.2.71
MEDIUM 4.3 The Download Manager plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 3.2.… wordfence
b4862cb6-110b-48ec-80fb-c25ab080838c
< 1.1.9
MEDIUM 4.3 The Flexible Cookies plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
b4772ab0-41cd-4b35-bda9-d72e0fd7b7a5
< 2.2.6
MEDIUM 4.3 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
b4595eed-ce5d-42f1-979e-cc37350d15d5 MEDIUM 4.3 The Dating theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 11.2.0. Thi… wordfence
b452fcc8-1359-439c-a255-91054c83d6aa
< 5.5.0
MEDIUM 4.3 The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable … wordfence
b437020c-31a3-413e-a1da-b4781da34f10
< 1.2.3
MEDIUM 4.3 The Contact Form 7 Connector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
b42178a9-2f73-48d2-a912-50efe0bec76e
< 6.4.6
MEDIUM 4.3 The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Ob… wordfence
b411a97b-2f1c-4feb-b1c7-bc5a1aab7f33 MEDIUM 4.3 The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… wordfence
b40e70ed-cdcb-4999-92a9-45bbd2515a3d
< 4.0.15
MEDIUM 4.3 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
b3fef149-a087-4ce3-9802-cf0c12f13885
< 1.3.2
MEDIUM 4.3 The Integration for WooCommerce and QuickBooks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… wordfence
b3f87bd6-b432-4bf8-9046-8d66b45f6a85
< 1.3.8
MEDIUM 4.3 The Legal Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
b3e12653-ddfe-4e02-9d9e-0263b9f71def
< 1.3.60
MEDIUM 4.3 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_c… wordfence
b3d9b755-1e6e-44ac-989a-201237f6dc9f MEDIUM 4.3 The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… wordfence
b3d27929-1955-4700-95b3-a6d399bf7cee
< 1.0.6
MEDIUM 4.3 The Manage User Columns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
b3c96e57-0300-4ea7-a0c6-5d060b6e979d MEDIUM 4.3 The DX Sources plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.… wordfence
b3c232b4-7c30-413b-83ff-49f47dc28117
< 1.2.10
MEDIUM 4.3 The Xpro Theme Builder For Elementor – FREE plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
b3b23544-71de-4da8-9fd5-6d9ef995ad7b
< 2.1.1
MEDIUM 4.3 The Himer theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. T… wordfence
b3ae17c3-9f65-4855-aed6-64d3ccb2ff0b
< 2.3.1
MEDIUM 4.3 The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct O… wordfence
b39d66de-6d83-4fb5-a78c-c46e4540c48c MEDIUM 4.3 The Woocommerce Customers Order History plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
b3900e4f-4ae4-4026-89df-b63bd869a763
< 3.1.14
MEDIUM 4.3 The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
b37ee395-aad8-4908-b3f7-c9f68ed4a4e6
< 3.9.13
MEDIUM 4.3 The Tutor LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
b3533123-a141-4a15-b8cd-46a2870ecbd6
< 2.4.6
MEDIUM 4.3 The Clone plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t… wordfence
← Prev 1411 1412 1413 1414 1415 1416 1417 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top