πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1419 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
afc7be69-5823-441a-8a0e-1a0cfdd2ce4d MEDIUM 4.3 The Photo Gallery Builder plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing ca… wordfence
af9ce573-88e7-488c-92c6-faae685c7035 MEDIUM 4.3 The SimaCookie plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
af96119c-e542-4922-bf5e-b063449ec587
< 7.13.2
MEDIUM 4.3 The Avada theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 7.13.2. This is due to missi… wordfence
af913bb1-eff6-47cd-9471-f74bafda1e52
< 2.7.0
MEDIUM 4.3 The Advanced Form Integration β€” Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass … wordfence
af7dc118-775f-471a-a2f9-49d6d77bd84c
< 3.6.12
MEDIUM 4.3 The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Insecure Direct Object Reference in all v… wordfence
af6c1d79-b33e-4f5e-a6c6-9827cba5dda6
< 4.6.0
MEDIUM 4.3 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request… wordfence
af6b7cba-56cc-4e78-a3c1-228eecb98120
< 1.4.14
MEDIUM 4.3 The Custom Thank You Page Customize For WooCommerce by Binary Carpenter plugin for WordPress is vulnerable to unauthoriz… wordfence
af59fcf6-4435-45f0-8904-ff520ea86157
< 1.6
MEDIUM 4.3 The WP Super Minify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
af59eb6d-1ffa-4593-9bfc-f910d907f6e0
< 3.7.8
MEDIUM 4.3 The Event Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
af55c470-b94d-49ee-8b72-44652dcccd73
< 4.4
MEDIUM 4.3 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a… wordfence
af4fdab3-18d1-4dc4-991c-24c4fdb6cb2a
< 1.23.10
MEDIUM 4.3 The MeetingHub for Zoom Meeting, Google Meet, Jitsi Meet, Webex, & Microsoft Teams | The All-in-One Webinar & Video Conf… wordfence
af4a21b4-9032-4c57-a762-6ad8ba772c63 MEDIUM 4.3 The ST Gallery WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
af37b5ab-e7ff-4a2a-98c3-decdf238a13f
< 1.5.110
MEDIUM 4.3 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Sensitive I… wordfence
af36719a-8f7d-46dc-a697-cfcbb08e45e2 MEDIUM 4.3 The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
af287dc4-a82a-4ccf-8878-6f9591fa5d33
< 2.2.1
MEDIUM 4.3 The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr… wordfence
af15ae80-dbce-4899-9604-82fdca222bf5 MEDIUM 4.3 The AHAthat Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
af076acb-f0a8-4f47-bfa6-74e20759f764
< 3.5.4
MEDIUM 4.3 The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
aefbf8d9-093b-4aaf-8a38-148a0b74ca1a MEDIUM 4.3 The Add Polylang support for Customizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
aee587cf-83c6-46ab-89a2-20d7e76e1e8b
< 2.3.3
MEDIUM 4.3 The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Cross-Site Request Fo… wordfence
aed630d4-7f8b-4b42-8209-aa8a536349da MEDIUM 4.3 The SensitiveTagCloud plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
aecf61bc-4d89-41ba-b99f-669193be64d1
< 4.1.3
MEDIUM 4.3 The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
aec4559a-4d96-49d3-8dc3-0210c78a798e
< 3.2.9
MEDIUM 4.3 The Solid Central – Site Management, Backups, Security, and Reporting plugin for WordPress is vulnerable to unauthoriz… wordfence
aea8b35a-9a30-4ce6-b79c-2e0a079ac939
< 8.6.5
MEDIUM 4.3 The MapSVG – Vector maps, Image maps, Google Maps plugin for WordPress is vulnerable to unauthorized access due to a m… wordfence
ae9c421c-925b-4c2d-b3f5-781c54a85c2e
< 1.3.2
MEDIUM 4.3 The Media Library Downloader plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
ae865f91-4c2a-4a6b-84a8-bd45c1febdb1
< 4.0.6
MEDIUM 4.3 The ARMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.5. T… wordfence
← Prev 1416 1417 1418 1419 1420 1421 1422 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top