πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1418 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b08ebc3b-ee89-4a4d-8a4c-8513e13b32b6
< 4.2.26
MEDIUM 4.3 The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to unauthorized access due to a m… wordfence
b088ac09-bb14-45d8-9771-9be4cf580c1c
< 3.3.2
MEDIUM 4.3 The Zoho ZeptoMail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.… wordfence
b082176c-9486-416c-8215-cdba4d6e5260
< 3.12.1
MEDIUM 4.3 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Reques… wordfence
b08194e9-6e6e-484c-bc5b-87235379d3b1
< 4.2.1
MEDIUM 4.3 The JCH Optimize plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.2.0. … wordfence
b07dc6ff-f88d-4c5a-8cd5-7c20f1755ece
< 1.1.5
MEDIUM 4.3 The Klamra Paycal for Aspaclaria plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions … wordfence
b07b46a6-8a5d-40cb-8af9-baf0f1722736
< 1.6.0
MEDIUM 4.3 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
b07194ee-3e2c-4fcc-933b-1b49e982b927 MEDIUM 4.3 The Simple Stripe plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.9… wordfence
b06a1b66-9057-4f16-878c-4fa66489f0ff
< 4.3.1
MEDIUM 4.3 The AWP Classifieds plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… wordfence
b056cc98-3bd8-493a-bbf4-9bcee2e52d24
< 1.0.6
MEDIUM 4.3 The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
b0520601-7e5c-412d-a8da-df1bf8ce28df
< 1.6.0
MEDIUM 4.3 The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to unauthorized access of data a… wordfence
b04ba117-da4b-445e-99c2-69a5e4f34a65
< 3.9.2
MEDIUM 4.3 The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.… wordfence
b0403adb-08c4-4697-a7d9-50e39d46cd43 MEDIUM 4.3 The BigContact plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.8.… wordfence
b03a9aaa-ce9a-47bf-8574-0eba92fcf0c5
< 1.3.4
MEDIUM 4.3 The XML Sitemap Generator for Google plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
b039eee2-767d-459e-9d7d-7a63eac12017 MEDIUM 4.3 The SMS Contact Form 7 Notifications by ClickSend plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
b03409ee-37bd-4c61-8a74-11fedac1d10f
< 1.1.35.1
MEDIUM 4.3 The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable… wordfence
b0224760-b492-4a00-bdf8-24a8db3ea3df MEDIUM 4.3 The WP-CORS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
b02198f5-10df-4c4c-beed-aec8acacaec9 MEDIUM 4.3 The WP SinoType plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
b01ce091-7d5a-43f4-bfb1-20e7502ca57b
< 0.15
MEDIUM 4.3 The Plugins Garbage Collector (Database Cleanup) plugin for WordPress is vulnerable to Cross-Site Request Forgery in ver… wordfence
b0121ef5-4b0b-47c5-8d3d-7d32c8e67c27
< 2.0.1
MEDIUM 4.3 The Logo Showcase with Slick Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
b00f98fd-2c6e-4e4d-baa2-1eca3f41a56f MEDIUM 4.3 The Social Photo Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
b002d1a1-a536-4865-b263-594390941ed4
< 0.9.7.4
MEDIUM 4.3 W3 Total Cache in versions 0.5 up to 0.9.7.3 does not sufficiently validate the "openssl_verify" result in "/services/Me… wordfence
aff10d5a-a2d0-461a-b52b-a25b647eaab4
< 3.10.5
MEDIUM 4.3 The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient aut… wordfence
aff013d9-9e0d-42e8-a351-f1278060e649
< 1.1.3
MEDIUM 4.3 The Sarada Lite theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2.… wordfence
afceaa5e-9098-449e-a1af-7dbd36461f6a MEDIUM 4.3 The Awesome Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
afca7b14-f3bb-4612-b81c-bde120b380ba MEDIUM 4.3 The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
← Prev 1415 1416 1417 1418 1419 1420 1421 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top