πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1424 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
aa5ee133-e38a-4dfe-975c-f194aa6e90b8 MEDIUM 4.3 The WP Knowledgebase plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
aa18de7f-e645-4d1b-90d5-d47ee7e1d52d
< 5.9
MEDIUM 4.3 The Tagembed plugin for WordPress is vulnerable to unauthorized access of functionality in versions up to, and including… wordfence
aa16ab9f-4fb1-43de-bfbb-bd6caf6a68dc MEDIUM 4.3 The Kopa Framework plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
aa15df6a-3411-4d69-8337-a3944ceae9ee
< 3.4.1
MEDIUM 4.3 The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
aa154536-9f9f-48c3-96c7-4091991e4f6c
< 3.3.69
MEDIUM 4.3 The LiquidPoll – Advanced Polls for Creators and Brands plugin for WordPress is vulnerable to unauthorized modificatio… wordfence
aa14cc6f-aeea-4be3-888b-8d4542b66309
< 2.4.4
MEDIUM 4.3 The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to Cross-Sit… wordfence
aa00fe53-dc65-4200-80bb-9167b4230194
< 1.2.2
MEDIUM 4.3 The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Ob… wordfence
a9e18f26-ddc2-4ed4-89e7-20c7c086f446
< 2.5.01
MEDIUM 4.3 The BuddyBoss Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
a9c500fc-0d85-41b1-a2b8-9c8ba372a6e3 MEDIUM 4.3 The Original texts Yandex WebMaster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
a9c1231c-b12f-40ef-8ecb-54505c97aa2d
< 1.8.5
MEDIUM 4.3 The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
a9c0677a-9e2e-4342-be04-cd7c5cae3b18
< 1.5.9
MEDIUM 4.3 The Beacon Lead Magnets and Lead Capture plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
a9b45e9b-57a6-4bfd-b9e4-d07780370f02
< 8.5.5
MEDIUM 4.3 The NEX-Forms – Ultimate Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
a99d0220-38af-40fe-8b9f-af173fc41248
< 7.2.2.3
MEDIUM 4.3 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
a98f6a68-5863-4147-86c4-8c19af469be3
< 1.3
MEDIUM 4.3 The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
a981e454-32ba-494d-b47f-769a1e544e16
< 3.6.7
MEDIUM 4.3 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Insecure Direct Object R… wordfence
a97de342-5802-4ad7-b255-635a5776a126 MEDIUM 4.3 The Simple Fixed Notice plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
a97d5ca2-a11f-4417-8447-9aa9d7108aa4 MEDIUM 4.3 The Bulk Term Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
a9565693-fd0b-4412-944c-81b3cd79492e
< 3.2.3
MEDIUM 4.3 The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to una… wordfence
a92d5176-4cf0-4a31-9dcc-a2dc3259d29b
< 6.4.6
MEDIUM 4.3 The Complianz | GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
a922bf72-192e-457f-9c33-59835e9aff2a
< 1.0.3
MEDIUM 4.3 The Mautic Integration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
a91bd1cf-ac63-4d65-b9fc-3fa2507cc27e
< 1.0.13
MEDIUM 4.3 The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capab… wordfence
a910fd44-4de1-41e8-8da2-d72a2f835797
< 0.9.4.1
MEDIUM 4.3 The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attack… wordfence
a90e5607-2c9a-4f3f-9f20-0ff1b8963a13 MEDIUM 4.3 The WooCommerce Single Page Checkout plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
a8f6cbfc-f5f2-4035-84bd-0e7a00cda194 MEDIUM 4.3 The Kallyas theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2. This … wordfence
a8f1e411-3060-4f1a-8a73-db33557aa3c6
< 1.13.62
MEDIUM 4.3 The Product Slider, Product Grid, Product Masonry plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
← Prev 1421 1422 1423 1424 1425 1426 1427 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top