πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1429 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a4ac5738-0ebe-480a-b2b7-f0568d668fa6
< 1.7.9
MEDIUM 4.3 The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF w… wordfence
a4a67ec6-ee13-4532-8213-d17dbf5f2c55
< 7.1.3
MEDIUM 4.3 The Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th… wordfence
a49d5e93-754d-4543-8066-911746fe6aee
< 4.3.0
MEDIUM 4.3 The Jobify - Job Board WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
a4997290-c7d5-48cb-92e1-b84b42bd213e
< 5.10.5.2
MEDIUM 4.3 The TheGem Demo Import (for WPBakery) plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
a48dcada-aafe-4af0-9d27-8ae2e86232a8 MEDIUM 4.3 The WP Social Bookmarking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
a4879ad0-8999-4856-bfbf-28c89092b4e2 MEDIUM 4.3 The Block Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
a48634d7-30c9-4124-87dd-93a303a969eb
< 2.5.0
MEDIUM 4.3 The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc… wordfence
a467ad30-8271-421c-8af4-8165fd60c03e
< 2.18.3
MEDIUM 4.3 The Lazy Load for Videos plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
a4647210-ba7e-4233-83d6-12572213f5fb
< 1.7.5
MEDIUM 4.3 The Premium version of the Checkout Field Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in ver… wordfence
a462789a-d311-47d7-9f54-190eaf5da03f
< 4.3.0
MEDIUM 4.3 The Analytify plugin for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to,… wordfence
a443e857-a915-4aa4-9879-1465d50544cc
< 29.0.0
MEDIUM 4.3 The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Sen… wordfence
a4420935-4952-4460-afc2-1c6df6965b3d
< 3.35.8
MEDIUM 4.3 The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exp… wordfence
a420a8b5-e43e-4c0d-86f3-b35f11efdf46
< 3.1.2
MEDIUM 4.3 The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… wordfence
a4178271-c09e-4094-a616-5a00d28f39a3
< 1.3.88
MEDIUM 4.3 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
a3fc4131-9cbe-4fb9-93bf-285701411aa7 MEDIUM 4.3 The Global Translator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
a3f1d836-da32-414f-9f2b-d485c44b2486
< 4.2.0
MEDIUM 4.3 The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in … wordfence
a3f0e97c-f41f-47ed-93c7-cff5915e9d01
< 4.3.1
MEDIUM 4.3 The SULly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3. Th… wordfence
a3f0556e-a875-4f88-b96c-a924f8fe01da
< 7.9.9
MEDIUM 4.3 The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to unauthoriz… wordfence
a39ca182-981b-4636-acd5-4c8a269858dd
< 1.0.7
MEDIUM 4.3 The WOLF plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. This … wordfence
a397a7f0-2f6a-48aa-9646-ae2abd410c48
< 1.00.04
MEDIUM 4.3 The Termin-Kalender plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
a3936c4b-2326-41dc-b7d6-a8cf43752ddb
< 2.5.1
MEDIUM 4.3 The myCred plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5. This … wordfence
a38e649d-00ad-4198-a96a-e280bc810cff
< 2.2.12
MEDIUM 4.3 The Sign-up Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
a3895b45-b103-4ba0-905c-611f5d1ba9a6 MEDIUM 4.3 The Fix Rss Feeds plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
a38386f1-5d5c-4ab4-b3b7-60bceb04730d
< 2.6.4
MEDIUM 4.3 The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to unauthorized ac… wordfence
a36dedad-da5e-440e-b626-95df0d154870
< 2.7.60
MEDIUM 4.3 The BuddyBoss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 2.7.… wordfence
← Prev 1426 1427 1428 1429 1430 1431 1432 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top