πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1431 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a298955e-c8e2-4732-a38e-4f7338a088bc
< 4.1.21
MEDIUM 4.3 The Eventin plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 4.1.20. This is … wordfence
a2926c11-c6a2-4988-89ed-42d9e0791b95
< 4.7.31
MEDIUM 4.3 WordPress Core is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.8.2. This makes i… wordfence
a28e3f3b-6f8d-4745-bb56-a7c9e973a4ca
< 10.3.0
MEDIUM 4.3 The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
a27eb4f9-3e8e-42bc-8808-fd47a17d5cd7
< 1.12.2
MEDIUM 4.3 The SMTP2GO for WordPress – Email Made Easy plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
a26a6f28-4a7f-421d-a69e-2afbe1367106
< 1.6.50
MEDIUM 4.3 The WooCommerce Brands plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
a250f678-1ec7-48ea-8b81-e5ef89992155
< 6.24.2
MEDIUM 4.3 The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers… wordfence
a228e60c-c91b-4a82-8b05-a0ffaed82524
< 3.5.14
MEDIUM 4.3 The Simple Sitemap – Create a Responsive HTML Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery… wordfence
a201aa76-8849-47a8-bc67-86a08a4159ea MEDIUM 4.3 The Huger for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
a1fc4ce9-ae96-4d8e-bf1c-941ed15d7d1a
< 2.5.2
MEDIUM 4.3 The Droip plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a… wordfence
a1fbb3a6-fcc2-47c5-a086-331e69292add
< 3.2.3
MEDIUM 4.3 The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
a1e51a99-f5d4-47d4-bead-00ca1f5f72c2
< 5.14.2
MEDIUM 4.3 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
a1e34a47-b025-469e-83da-ec6e1ea40d4d MEDIUM 4.3 The Flatsome theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
a1e02c2d-a38a-495c-9c37-098049297be2 MEDIUM 4.3 The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF… wordfence
a1d8adf9-a529-45eb-9c59-8f43049de460 MEDIUM 4.3 The DN Popup plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.… wordfence
a1bf7283-2ad7-4a4e-b5b7-7b944c5001a0 MEDIUM 4.3 The Gmedia Photo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
a1b99ea1-109e-4632-9439-3ffbb10f0839
< 1.8.7
MEDIUM 4.3 The Signature Add-On for Gravity Forms plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
a1b3bcad-4bee-4848-8d68-0aacaf199910
< 2.5.8
MEDIUM 4.3 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions … wordfence
a1ad32fb-929e-4181-8789-df50a77a71ef
< 2.0.15
MEDIUM 4.3 The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to authorization bypass in versions up to, … wordfence
a1a3c767-465b-4307-b114-7144ff9ef47b
< 2.0.8
MEDIUM 4.3 The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Cross-Site Reque… wordfence
a199e16a-80a7-4471-afc6-4942c7de31bf
< 3.7.1
MEDIUM 4.3 The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vuln… wordfence
a189e436-e8af-4379-aa6e-2d1a4a2d4bfa MEDIUM 4.3 The Bulk images optimizer: Resize, optimize, convert to webp, rename … plugin for WordPress is vulnerable to unauthori… wordfence
a1877e8a-0ae1-4277-93ac-7bc56fd8c3ce MEDIUM 4.3 The Wishlist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
a1859dca-d771-470c-ae4a-48246977212c
< 1.9.4
MEDIUM 4.3 The Big Store plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.3. … wordfence
a184090c-0281-4d8d-bd4d-256b4ed826dc MEDIUM 4.3 The Smart YouTube PRO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
a1825e57-b59f-4c57-8008-640717e05eb3
< 1.8.3
MEDIUM 4.3 The Frisbii Pay plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
← Prev 1428 1429 1430 1431 1432 1433 1434 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top