πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1428 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a590ed63-ccec-4f20-961d-62c1f08781b0 MEDIUM 4.3 The Fast Custom Social Share by CodeBard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
a57d6585-bffb-41c4-9301-5f9e2f16eb2c MEDIUM 4.3 The WooCommerce Orders & Customers Exporter plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
a57509c5-6535-4a73-a138-a03805746754 MEDIUM 4.3 The TinyNav plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. … wordfence
a554b365-b54b-4696-87f6-df5099e15708 MEDIUM 4.3 The WPsoonOnlinePage plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
a54e9aa6-943d-4f76-81af-3424a23f9313
< 5.9
MEDIUM 4.3 The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthoriz… wordfence
a548e71f-4f36-4a29-8293-474e119f09cc
< 1.7.1
MEDIUM 4.3 The Subscribers Text Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
a54841af-65ce-4434-a67e-79ea673ec8f9
< 2.0.4
MEDIUM 4.3 The WooCommerce Bookings plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
a533ddd4-cf89-4bf9-981e-2fdd4ff4d414
< 1.0.22
MEDIUM 4.3 The EmpowerWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.21. … wordfence
a531730a-8505-4461-aeff-94b04778c8b9 MEDIUM 4.3 The Labinator Content Types Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
a528a2b5-55e5-46e4-8f04-0d2b49f2f683
< 3.8.17
MEDIUM 4.3 The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users A… wordfence
a5276227-9bd4-4ad8-a6b7-ac7d05e8b056
< 2.2
MEDIUM 4.3 The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
a52325f9-51b5-469c-865e-73a22002d46f
< 1.7.2
MEDIUM 4.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing cap… wordfence
a51d081b-344d-4a07-b069-473548b7edbb
< 6.7
MEDIUM 4.3 The Oneline Lite theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
a4ffb3ef-9d77-463f-92c4-4bc799ac16aa
< 6.5.2
MEDIUM 4.3 The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
a4fd7e76-4d8b-4e4d-9ae9-c7f9933f8324
< 2.1.8
MEDIUM 4.3 The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… wordfence
a4f7211b-0ff0-406e-9a0a-2dd7b1314d6d
< 7.0.18
MEDIUM 4.3 The WP Full Stripe Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
a4ea53bd-2ce7-4dce-8c57-51ba81838f1a
< 2.2.0
MEDIUM 4.3 The CodeBard's Patron Button and Widgets for Patreon plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
a4e24622-5ff7-4261-a07b-4c096b77fb13
< 2.8.3
MEDIUM 4.3 The WooCommerce - Social Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
a4d6dcb5-a97a-4e80-b0dc-5649c9867374
< 5.0.31.decaf
MEDIUM 4.3 The Event Espresso 4 Decaf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
a4cd49b2-ff93-4582-906b-b690d8472c38
< 7.1.1
MEDIUM 4.3 The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_wp_option' shortcode in v… wordfence
a4c8d390-145a-4926-99e9-b386dfe5e6ac
< 1.3.4
MEDIUM 4.3 The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
a4c6d924-c741-4044-b6e2-a95793c606e2 MEDIUM 4.3 The Editor Custom Color Palette plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
a4c32896-bd0d-4bdb-845d-ca5a9aa5d5c0 MEDIUM 4.3 The Categorify – WordPress Media Library Category & File Manager plugin for WordPress is vulnerable to unauthorized ac… wordfence
a4b847b5-9deb-41c4-b976-725249e0098e
< 2.4.7
MEDIUM 4.3 The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to una… wordfence
a4aed6ba-23a2-46b6-b7e1-7b7e462b1f5b
< 1.0.44
MEDIUM 4.3 The Google Maps CP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
← Prev 1425 1426 1427 1428 1429 1430 1431 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top