πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1425 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
aa7276bb-6a9b-4cbd-8333-14c4dfac4108
< 1.11
MEDIUM 4.3 The Debug plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10. This … wordfence
aa657530-7c85-4399-94bb-feaa7d21a47a
< 26.6.3
MEDIUM 4.3 The Betheme theme for WordPress is vulnerable to authorization bypass in versions up to, and including, 26.6.2. This is … wordfence
aa5ee133-e38a-4dfe-975c-f194aa6e90b8 MEDIUM 4.3 The WP Knowledgebase plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
aa18de7f-e645-4d1b-90d5-d47ee7e1d52d
< 5.9
MEDIUM 4.3 The Tagembed plugin for WordPress is vulnerable to unauthorized access of functionality in versions up to, and including… wordfence
aa16ab9f-4fb1-43de-bfbb-bd6caf6a68dc MEDIUM 4.3 The Kopa Framework plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
aa15df6a-3411-4d69-8337-a3944ceae9ee
< 3.4.1
MEDIUM 4.3 The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
aa154536-9f9f-48c3-96c7-4091991e4f6c
< 3.3.69
MEDIUM 4.3 The LiquidPoll – Advanced Polls for Creators and Brands plugin for WordPress is vulnerable to unauthorized modificatio… wordfence
aa14cc6f-aeea-4be3-888b-8d4542b66309
< 2.4.4
MEDIUM 4.3 The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to Cross-Sit… wordfence
aa00fe53-dc65-4200-80bb-9167b4230194
< 1.2.2
MEDIUM 4.3 The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Ob… wordfence
a9e18f26-ddc2-4ed4-89e7-20c7c086f446
< 2.5.01
MEDIUM 4.3 The BuddyBoss Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
a9c500fc-0d85-41b1-a2b8-9c8ba372a6e3 MEDIUM 4.3 The Original texts Yandex WebMaster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
a9c1231c-b12f-40ef-8ecb-54505c97aa2d
< 1.8.5
MEDIUM 4.3 The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
a9c0677a-9e2e-4342-be04-cd7c5cae3b18
< 1.5.9
MEDIUM 4.3 The Beacon Lead Magnets and Lead Capture plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
a9b45e9b-57a6-4bfd-b9e4-d07780370f02
< 8.5.5
MEDIUM 4.3 The NEX-Forms – Ultimate Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
a99d0220-38af-40fe-8b9f-af173fc41248
< 7.2.2.3
MEDIUM 4.3 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
a98f6a68-5863-4147-86c4-8c19af469be3
< 1.3
MEDIUM 4.3 The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
a981e454-32ba-494d-b47f-769a1e544e16
< 3.6.7
MEDIUM 4.3 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Insecure Direct Object R… wordfence
a97de342-5802-4ad7-b255-635a5776a126 MEDIUM 4.3 The Simple Fixed Notice plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
a97d5ca2-a11f-4417-8447-9aa9d7108aa4 MEDIUM 4.3 The Bulk Term Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
a9565693-fd0b-4412-944c-81b3cd79492e
< 3.2.3
MEDIUM 4.3 The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to una… wordfence
a92d5176-4cf0-4a31-9dcc-a2dc3259d29b
< 6.4.6
MEDIUM 4.3 The Complianz | GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
a922bf72-192e-457f-9c33-59835e9aff2a
< 1.0.3
MEDIUM 4.3 The Mautic Integration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
a91bd1cf-ac63-4d65-b9fc-3fa2507cc27e
< 1.0.13
MEDIUM 4.3 The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capab… wordfence
a910fd44-4de1-41e8-8da2-d72a2f835797
< 0.9.4.1
MEDIUM 4.3 The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attack… wordfence
a90e5607-2c9a-4f3f-9f20-0ff1b8963a13 MEDIUM 4.3 The WooCommerce Single Page Checkout plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
← Prev 1422 1423 1424 1425 1426 1427 1428 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top