πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1430 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a35a66c6-2a86-4f6e-b28e-d79e13489a49
< 2.4.4
MEDIUM 4.3 The Homey theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This … wordfence
a349b220-5b42-4b98-869f-ce8399fe7ec9
< 2.0.3
MEDIUM 4.3 The Easy restaurant menu manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
a3473b5e-2f50-4845-9cfa-d19129f2a430
< 2.5.4
MEDIUM 4.3 The ApplyOnline – Application Form Builder and Manager plugin for WordPress is vulnerable to unauthorized access due t… wordfence
a3425d78-1e24-4224-bfdc-a3e11735384f
< 0.4.12
MEDIUM 4.3 The Customify theme for WordPress is vulnerable to Cross-Site Request Forgery in version 0.4.11. This is due to missing … wordfence
a33c8a80-e11e-403d-9eb0-e1c5b59204b0
< 5.7.6
MEDIUM 4.3 The AutomateWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.7.5… wordfence
a3374f89-ae63-45bb-b6a6-9689e2513e69
< 1.4.3
MEDIUM 4.3 The Attesa Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.2 … wordfence
a335c917-3fff-4079-bb38-64cd665c5c38
< 2.0.8
MEDIUM 4.3 The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cr… wordfence
a32f4dda-f22e-488e-b57a-efc8de8da036 MEDIUM 4.3 The AnsPress – Question and answer plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… wordfence
a3157123-2eea-4f8b-bfc1-07633ad84c2b
< 4.1.20
MEDIUM 4.3 The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to unaut… wordfence
a30b3774-df88-49a6-89ec-2e771abed11c
< 1.4.2
MEDIUM 4.3 The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to unauthorized m… wordfence
a2f8b6b3-fb5a-4244-8b97-56375c2f2ff1
< 2.22.16
MEDIUM 4.3 The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … wordfence
a2f7cce4-bb0e-4d71-bb70-75d9b298384e MEDIUM 4.3 The Media Library File Download plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
a2f3fcd1-6dff-409b-b8c1-46c5485980ee
< 1.3.4
MEDIUM 4.3 The WishSuite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.3. … wordfence
a2f118fc-d99a-4713-865e-2da7a9e20db5
< 3.12.1
MEDIUM 4.3 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Reques… wordfence
a2f0e910-40e2-4ad0-a3de-fe8dd8a38652 MEDIUM 4.3 The Mailing Group Listserv plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
a2edfda3-7c60-424e-bcf7-384958a4eaa9 MEDIUM 4.3 The WPShapere Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
a2e70691-4de9-4b12-babf-bebe267a780b
< 5.9.28
MEDIUM 4.3 The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for… wordfence
a2e2bd61-3187-4992-a3ae-1b5d88d1b90f
< 4.1.21
MEDIUM 4.3 The Eventin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.1… wordfence
a2cdf6d8-8f7b-4ed1-b5c6-16bdd1211237 MEDIUM 4.3 The WP Ride Booking – Best Taxi Booking Solution for WordPress plugin for WordPress is vulnerable to Cross-Site Reques… wordfence
a2c6aa0f-874b-40fa-aa7a-4c15fa162f6a
< 3.26.0
MEDIUM 4.3 The Wordpress Auto Spinner plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
a2c3a01c-af77-4abc-b33c-b637d55e0be2
< 3.7.23
MEDIUM 4.3 The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulner… wordfence
a2ba21cd-d8f3-402a-b067-1758937d9eb4
< 3.3.9
MEDIUM 4.3 The WP-Advanced-Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
a2b6ecc1-8957-49b4-941a-a327ae21dd05
< 4.2.10
MEDIUM 4.3 The Adminify plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.2.… wordfence
a2b2dd36-eca8-4d80-80f5-783f9402dd3c
< 1.5.3.7
MEDIUM 4.3 The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress… wordfence
a2a892ed-930a-49c8-a11f-3ba408d1b3aa MEDIUM 4.3 The Custom Sidebars by ProteusThemes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
← Prev 1427 1428 1429 1430 1431 1432 1433 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top