🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1426 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a8f6cbfc-f5f2-4035-84bd-0e7a00cda194 MEDIUM 4.3 The Kallyas theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2. This … wordfence
a8f1e411-3060-4f1a-8a73-db33557aa3c6
< 1.13.62
MEDIUM 4.3 The Product Slider, Product Grid, Product Masonry plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
a8e57528-010f-4ec6-917b-4cd8c3fdbd58
< 1.1
MEDIUM 4.3 The Mavix Education theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
a8e2bff6-3d2a-43d7-b26d-b520e3b4c709 MEDIUM 4.3 The wp-cyr-cho | Конвертира кирилски символи в латиниски plugin for WordPress is vuln… wordfence
a8db1624-e391-4b74-ad15-668b700b367d
< 2.0.5
MEDIUM 4.3 The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
a8d396fe-225d-47c5-be86-261f73eb08a1
< 1.5.0
MEDIUM 4.3 The Bitly URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
a8c29cbd-6c39-4a54-a2a2-bc4c8feeeb70
< 1.6.0
MEDIUM 4.3 The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up … wordfence
a8be9c76-08aa-4d41-8599-cc3494be7e58
< 2.2.0
MEDIUM 4.3 The WooCommerce Product Attachment plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
a8b0d708-4f74-4e6d-9581-f65caf976d45 MEDIUM 4.3 The WooCommerce Login Redirect plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
a8b0bad8-7ee6-4c7c-95da-7adf37c9cb1f
< 2.1.69
MEDIUM 4.3 The WooCommerce Products Vendor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to… wordfence
a8ae5712-09a8-45a4-9f79-3e5b7786e652
< 4.35
MEDIUM 4.3 The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is v… wordfence
a8a7936e-5ca8-4055-a23c-c9d39e9b92d5 MEDIUM 4.3 The Business Hours for WPBakery – Worker plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
a8a3ba35-3cc0-4a6b-bb96-6ae5a83e5ad6
< 4.2.5
MEDIUM 4.3 The MainWP Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
a8a0fca4-b308-4f17-85b4-22ac111d6207
< 1.3
MEDIUM 4.3 The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
a8a05986-46e2-49eb-b196-d5c36b03a394
< 2.0.19.11
MEDIUM 4.3 The WP Booking System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
a8931773-b656-4d04-9a38-5d10ce050311 MEDIUM 4.3 The IS-theme-companion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
a88e43ac-d571-46b0-aace-970e113e799e
< 1.4.8
MEDIUM 4.3 The Seznam Webmaster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
a87f610a-c1ef-4365-bd74-569989587d41
< 1.1.3
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
a86fc949-6caf-48b7-beda-ca0c653c9b29
< 1.0.82
MEDIUM 4.3 The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable… wordfence
a86a694b-5e45-4e94-a22c-2c5faa7172a2 MEDIUM 4.3 The WP Power Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
a864cddc-b627-46e3-a9b2-f0e051221728
< 7.42
MEDIUM 4.3 The WP Custom Admin Interface plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
a853bbb4-9866-4bc4-94da-d7826863d23b
< 4.7.6
MEDIUM 4.3 The Super Page Cache for Cloudflare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
a84aa4fd-9df2-43c7-aa2c-28d41623b6dd MEDIUM 4.3 The m1.DownloadList plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl… wordfence
a841456c-2a01-4caf-bebe-e018b92697d8
< 3.29
MEDIUM 4.3 The NextGEN Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… wordfence
a83c88c8-3aed-4c97-9c4c-28a79a1e8c80
< 3.2.9
MEDIUM 4.3 The Ni WooCommerce Cost Of Goods plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
← Prev 1423 1424 1425 1426 1427 1428 1429 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top