πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1422 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ac47ccff-6e36-4bc2-b7f3-70deb3d8b3b7
< 2.5.1
MEDIUM 4.3 The Credova Financial plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
ac34e369-de9e-4b13-8858-0b4300aef5f8
< 1.0.3
MEDIUM 4.3 The WP2HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2… wordfence
ac2b2862-a56c-456e-a621-8b10b30235be
< 2.3.4
MEDIUM 4.3 The WPC Admin Columns plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ… wordfence
ac245316-228e-4508-b3fe-f7071fb1bc8e
< 2.0.1
MEDIUM 4.3 The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Server-Side Request Forgery in version… wordfence
ac23bca5-38dd-4460-83ce-5f7fc8a1f6a0 MEDIUM 4.3 The cForms – Light speed fast Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
ac20b454-a5e5-4ff6-a5bf-9c3c339321d8
< 2.10.3
MEDIUM 4.3 The Mediavine Control Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
ac200da9-6a02-416a-aeb2-344eba4fcc3e MEDIUM 4.3 The BERTHA AI. Your AI co-pilot for WordPress and Chrome plugin for WordPress is vulnerable to unauthorized access due t… wordfence
ac176fdf-3ebc-47b3-8404-c2423d141029 MEDIUM 4.3 The CubePoints plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.… wordfence
ac13f402-8a36-448f-87d4-48179a9699c6
< 1.27
MEDIUM 4.3 The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to unauthorized modification of data due to… wordfence
ac111175-2059-41dc-afa2-a659da3adaca
< 2.2.3
MEDIUM 4.3 The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
ac07cc53-311d-465e-a00f-8aa37fec2ad9
< 7.6.3
MEDIUM 4.3 The admin-site-enhancements-pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
ac05441d-137e-433a-86bd-a702ec664db0
< 2.3.2
MEDIUM 4.3 The Autopost for X (formerly Autoshare for Twitter) plugin for WordPress is vulnerable to unauthorized access due to a m… wordfence
abf1ace3-e066-4f28-9f37-3e9fa79aef7d
< 9.6.6
MEDIUM 4.3 The Salon booking system plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
abee822e-b929-435a-86c2-57901424f1a0
< 4.0.4
MEDIUM 4.3 The Wow Skype Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
abebfbc4-37ed-44d5-a35d-d6ad87346f3a
< 5.3.5
MEDIUM 4.3 The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to S… wordfence
abdd2653-d50c-4eee-9cab-36519fd2b209
< 1.2.1
MEDIUM 4.3 The The Conference theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2… wordfence
abcb2e9f-a6f1-40c3-b419-e2f65ec5dd41 MEDIUM 4.3 The AGP Font Awesome Collection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
abaebd3b-69ab-4e9b-a528-c9d846e62238
< 3.3.2
MEDIUM 4.3 The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing c… wordfence
ab8f8370-50bd-48c8-89e1-8b19b51f78b5
< 2.3.4
MEDIUM 4.3 In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could… wordfence
ab88f0cf-971f-43e1-b6b7-4eb55188ecc8
< 2.5.3
MEDIUM 4.3 The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for … wordfence
ab8659e1-5880-4738-99ed-e671449c6878
< 3.5.8
MEDIUM 4.3 The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
ab844a05-80e0-42c7-981c-dea3a18cf4d5
< 6.15.10
MEDIUM 4.3 The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on t… wordfence
ab7c8926-c762-49b1-bc97-4b7a2f4f97fc
< 3.2.4
MEDIUM 4.3 Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plu… wordfence
ab795923-2ec0-49eb-a911-56a74d90ca3f
< 1.6.1
MEDIUM 4.3 The Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
ab78f245-ab2d-4e9a-bd43-caa3afd1366b
< 3.4.135
MEDIUM 4.3 The Church Admin plugin for WordPress is vulnerable to Unauthenticated Backup Disclosure in versions up to, and includin… wordfence
← Prev 1419 1420 1421 1422 1423 1424 1425 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top