πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1416 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b2840b9e-1baf-460c-ba11-43e4279ece27
< 4.10.39
MEDIUM 4.3 The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to… wordfence
b276acdf-7372-4d08-a40b-f5a46a3d3b28
< 2.0.0
MEDIUM 4.3 The People Lists plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
b258e85e-eb1d-441a-ab99-c9604fb53656
< 5.0.2
MEDIUM 4.3 The Nexter Blocks plugin for WordPress is vulnerable to Payment Bypass in versions up to, and including, 5.0.1. This is … wordfence
b2438f64-2318-4345-99dd-f2266b2a5ca4 MEDIUM 4.3 The WooCommerce Shop Page Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
b243722e-6510-48bd-be26-95ccbe79fa57
< 5.38.2
MEDIUM 4.3 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
b2436028-9ac2-4232-bccf-26019a26e186
< 5.7.3
MEDIUM 4.3 The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Di… wordfence
b2296800-93d6-48fa-aa09-3d28fa6371d7
< 1.7.2
MEDIUM 4.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missi… wordfence
b228f8b1-dd68-41ee-bc49-6a62e5267233
< 1.7.2
MEDIUM 4.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
b2253753-f1ba-4cca-9e83-7532add6a077 MEDIUM 4.3 The Soccer Live Scores plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
b20b4eba-54df-4e08-ba4c-96f8bb463125
< 6.7.0
MEDIUM 4.3 The Mercado Pago payments for WooCommerce plugin is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
b1f4f428-93b1-4a29-9ac5-55d2020ab3c5
< 2.0.2
MEDIUM 4.3 The CBX Bookmark & Favorite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
b1e7bb04-28b4-407c-910b-e37a7e26682e
< 1.2.5
MEDIUM 4.3 The Simple Googlebot Visit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
b1e1db3f-1ebc-4f16-b2d8-8bce9c51b3db
< 3.8.13
MEDIUM 4.3 The Weather Station plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… wordfence
b1c8aa41-0362-47b8-afb0-80b6194b9bc3
< 1.4.6
MEDIUM 4.3 The Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery plugin for WordPress is vulnerable to … wordfence
b1c6261f-4657-4e6e-ae23-5fa44790aa12
< 2.4.0.1
MEDIUM 4.3 The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are … wordfence
b1c609fc-f719-4e2a-aaa6-80dc34025142 MEDIUM 4.3 The WP Permalink Translator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
b1c2712d-0865-4759-98da-1e11a26f2466
< 1.0.7.5
MEDIUM 4.3 The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
b1c0f8f3-22fe-4139-93bb-0e9bacf9dafb
< 1.1.7
MEDIUM 4.3 The Booking Ultra Pro plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capabil… wordfence
b1beb4ab-aa1d-47bb-8031-6e2974b844f5 MEDIUM 4.3 The VW Automobile Lite theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
b1b3f067-467f-4d8f-87bc-ee4a238b4019 MEDIUM 4.3 The Custom WooCommerce Checkout Fields Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve… wordfence
b1af4be1-a9d6-4f44-91b3-22cf3130cc34
< 2.5.7
MEDIUM 4.3 The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
b1a85bc2-0b00-4635-86f6-26e96cc0616e
< 1.1.4
MEDIUM 4.3 The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
b1a82073-ab63-42dd-9bc0-d21f53a5af25
< 0.0.4
MEDIUM 4.3 The HUMN-1 AI Website Scanner & Human Certification by Winston AI plugin for WordPress is vulnerable to unauthorized mod… wordfence
b1a12f7a-0f0d-47df-9266-4680d86f7e02
< 1.7.9
MEDIUM 4.3 The Gift Message for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
b19d0156-1fd9-4c18-be47-bce633b2f704
< 3.1.4
MEDIUM 4.3 The Intuitive Custom Post Order plugin for WordPress is vulnerable to authenticated settings change in versions up to an… wordfence
← Prev 1413 1414 1415 1416 1417 1418 1419 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top