πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1427 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a6bef410-8706-4440-b50f-08824ef754f6
< 2.1.1
MEDIUM 4.3 The PopupAlly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1… wordfence
a6b02846-61be-4571-921d-53df5493f856
< 3.3.52
MEDIUM 4.3 The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
a69782f0-aa61-4049-8339-7f27f4b6c36b
< 6.9.2
MEDIUM 4.3 WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collab… wordfence
a68dac5d-b07b-40c1-aad1-73e2c8d0f927
< 3.9.2
MEDIUM 4.3 The Hummingbird plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
a68b8df9-9b50-4617-9308-76a2a9036d7a
< 5.4.9
MEDIUM 4.3 The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8… wordfence
a683eeac-70a1-449c-b0ae-b28b3ef4c795 MEDIUM 4.3 The X Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
a67562c0-56e9-4b75-b0cf-ed408f4bfa2b
< 1.2.0
MEDIUM 4.3 The Car Rental Manager for WordPress – Online Vehicle Booking System plugin for WordPress is vulnerable to unauthorize… wordfence
a673f9f9-ad32-4dcf-bbbb-115a5339c415
< 4.0.1
MEDIUM 4.3 The UiChemy β€” Figma Converter for Elementor, Gutenberg and Bricks plugin for WordPress is vulnerable to unauthorized a… wordfence
a6702470-8ad3-45f0-9e90-9819e6a5b6dc MEDIUM 4.3 The RealtyCandy IDX Broker Extended plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
a669f42d-aed7-41a8-8069-f778c5fa48d4
< 1.6.5
MEDIUM 4.3 The Simple calendar for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
a66388d6-cf78-48b2-9363-53d1f72d1ff0
< 1.5.1
MEDIUM 4.3 The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, whi… wordfence
a65ce746-c356-4879-b348-688b2256fc67 MEDIUM 4.3 The Newsletter Popup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
a647f60b-233d-46f2-8837-b7c9bacd9958 MEDIUM 4.3 The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to unauthor… wordfence
a61c5999-6e7f-4ff9-8ed9-e3e2df9ceb6b
< 2.7.2
MEDIUM 4.3 The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
a60a9981-c945-4438-a844-f7942b86c4c0
< 1.2.9
MEDIUM 4.3 Integration for Contact Form 7 HubSpot is vulnerable to Open Redirects in versions up to, and including, 1.2.8. This is … wordfence
a604df5d-92b3-4df8-a7ef-00f0ee95cf0f
< 3.9.7
MEDIUM 4.3 The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the m… wordfence
a5e9cfd3-8066-4d75-8bb3-151815850870 MEDIUM 4.3 The AgreeMe Checkboxes For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
a5e7a994-c489-4aea-a9bb-898bc92cae4e
< 1.0.260
MEDIUM 4.3 The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
a5dd354f-080f-4be9-837e-eed48037f140
< 1.0.7
MEDIUM 4.3 The ContentMX Content Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
a5d19abc-4a11-4845-b41b-a7169983ca7d MEDIUM 4.3 The OpenHook plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.1. T… wordfence
a5be103f-e174-47f9-8a1b-bb0d073c54e4
< 5.8.0
MEDIUM 4.3 The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Di… wordfence
a5bc6097-d6ed-4598-b3c8-9159d5ce04ee
< 7.33
MEDIUM 4.3 The WP Custom Admin Interface plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
a5a93e3f-54c6-4970-96fd-fab0e81f7034 MEDIUM 4.3 The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
a5a5f8c2-3fd6-4d31-a3b5-60bdb8c18491
< 2.0
MEDIUM 4.3 The Custom Twitter Feeds (Tweets Widget) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
a59ddc3b-5ef8-4438-81be-af7cd49660e8
< 7.5.0
MEDIUM 4.3 The Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools plugin for WordPress is vu… wordfence
← Prev 1424 1425 1426 1427 1428 1429 1430 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top