πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1423 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ab6dd645-8831-49bc-b6b1-bb153ef79204
< 5.2.0
MEDIUM 4.3 The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized a… wordfence
ab68a08d-a6d4-4424-a7bf-219951f752fa MEDIUM 4.3 The Comparison Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
ab60edf0-0912-48d5-ae02-18b366c1d72b MEDIUM 4.3 The LMSACE Connect – WooCommerce Moodleβ„’ LMS Integration plugin for WordPress is vulnerable to unauthorized access d… wordfence
ab5d87d2-f3cb-4926-9cbf-acdbe9169f64
< 5.8.6
MEDIUM 4.3 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
ab57f010-4fd2-40c2-950f-c03888521c8f
< 3.1.1
MEDIUM 4.3 The Coupon Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.… wordfence
ab382c09-667b-42b9-b373-834a5f5ae9e2
< 1.2.5
MEDIUM 4.3 The Lawyer Landing Page theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
ab2b2a9d-fadd-4056-bb66-f1a070eb0361
< 6.3.3
MEDIUM 4.3 The ThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & More p… wordfence
ab2a4903-2c69-48da-bd4a-79b39b78806c
< 2.4.0
MEDIUM 4.3 The Custom Order Status for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
ab1bd64b-8575-4ab4-bca5-8d5ce6f476d1
< 1.4.16
MEDIUM 4.3 The Category Slider for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to missi… wordfence
ab1053e4-5135-49cc-a81b-9cf66e93bfef MEDIUM 4.3 The WP Quick Contact Us plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
ab0a61e7-6814-4773-af44-e42cffb1f480
< 1.9.29
MEDIUM 4.3 The Google Adsense & Banner Ads by AdsforWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
ab015cb4-0b1e-40ff-ab9b-6c03eed3142f
< 20.2
MEDIUM 4.3 The Taboola plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.1. Th… wordfence
aaf62045-b9ce-40d7-92b3-7ab683e5a08c
< 6.5.5
MEDIUM 4.3 The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Si… wordfence
aae70da2-fcd8-4e33-8f38-5e19e0c14733
< 5.2.4
MEDIUM 4.3 The All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce plugin for WordPress is vulnerable to C… wordfence
aad57a68-c385-491f-a5a2-32906df4b52b
< 2.11.1
MEDIUM 4.3 The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and incl… wordfence
aacfbc61-83a0-4876-80da-3b78e0ac6f31
< 4.1.3
MEDIUM 4.3 The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
aac9db5d-24fe-4136-b73d-8098c3dd4965
< 3.19.0
MEDIUM 4.3 The Stackable plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
aa9efe66-43e3-4711-bbe6-2a7bb383983e
< 2.1.8
MEDIUM 4.3 The Content Pilot – Autoblogging & Affiliate Marketing Suite plugin for WordPress is vulnerable to unauthorized access… wordfence
aa93cf13-0578-447e-8b03-24f5f48fc782
< 1.2.8
MEDIUM 4.3 The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
aa8d5feb-2ae9-44b8-90b5-9fc67226855a
< 23.5
MEDIUM 4.3 The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … wordfence
aa830c67-2860-489f-aa67-c7cc74437709
< 2.4.7
MEDIUM 4.3 The wpForo Forum plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu… wordfence
aa7fe608-55cf-4299-993e-cb262dd74880
< 2.4.19
MEDIUM 4.3 The Rife Free theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.18. … wordfence
aa7c3513-cef2-4f8d-b3e2-1bb8e52e76df MEDIUM 4.3 The PawFriends - Pet Shop and Veterinary WordPress Theme theme for WordPress is vulnerable to Insecure Direct Object Ref… wordfence
aa7276bb-6a9b-4cbd-8333-14c4dfac4108
< 1.11
MEDIUM 4.3 The Debug plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10. This … wordfence
aa657530-7c85-4399-94bb-feaa7d21a47a
< 26.6.3
MEDIUM 4.3 The Betheme theme for WordPress is vulnerable to authorization bypass in versions up to, and including, 26.6.2. This is … wordfence
← Prev 1420 1421 1422 1423 1424 1425 1426 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top