πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1432 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a175d2b2-0a35-4c5a-b05b-4d334e444e85
< 2.4.1
MEDIUM 4.3 The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a mis… wordfence
a1743b26-861e-4a61-80de-b8cc82308228
< 1.1.3
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
a16ef2b8-071b-440b-9d24-9755d2c4bb93 MEDIUM 4.3 The Rentals theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.13.1. Th… wordfence
a16b8075-1b09-47b9-8447-8b424ffaa5aa
< 9.0
MEDIUM 4.3 The Bulk Product Sync – Bulk Product Editor for WooCommerce with Google Sheetsβ„’ plugin for WordPress is vulnerable t… wordfence
a1652672-a429-4aac-8931-993de4079114 MEDIUM 4.3 The reCAPTCHA Jetpack plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
a162132a-f893-42fa-85f1-b42f738891a4
< 6.1.5
MEDIUM 4.3 The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized modificat… wordfence
a1529c89-5c5e-4a2d-be31-b55d2907c9b6
< 2.4.9
MEDIUM 4.3 The Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi… wordfence
a14e110f-0850-44f4-8de3-95a654096ae8
< 2.2.7
MEDIUM 4.3 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
a143d611-9e22-49d1-9a9f-12f1c45685c4
< 7.1.2
MEDIUM 4.3 The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Chang… wordfence
a1426809-b245-4868-be87-c96b3c5c05f9
< 7.1.2
MEDIUM 4.3 The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_get_option' shortcode in … wordfence
a128018b-f19b-4b18-a53c-cf1310d3d0e7 MEDIUM 4.3 The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6… wordfence
a127f1dc-9343-46d4-8ce2-7d0d2a7a960c
< 5.0.14
MEDIUM 4.3 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for Word… wordfence
a124da63-01a4-44d8-985b-cacef58ea9a3
< 2.4.0
MEDIUM 4.3 The EPROLO Dropshipping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… wordfence
a10278f1-3229-46c8-9da5-1fa8e34eef83
< 3.2.5
MEDIUM 4.3 The Coupons and Deals plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
a0ee9b26-4e7f-475f-b42b-5af40b78cbca
< 3.9.1
MEDIUM 4.3 The I Recommend This plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
a0e80e63-f4f7-44cc-ae29-72e7847d7448
< 5.47.0
MEDIUM 4.3 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing c… wordfence
a0e3668a-b76a-40b6-8697-c62a00904b7a
< 6.03
MEDIUM 4.3 The Sendle Shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6… wordfence
a0de486b-1ad9-440f-b2f8-b0a2a9af4d0f
< 3.7
MEDIUM 4.3 The WPTouch plugin for WordPress is vulnerable to an open redirect in versions before 3.7. This allows attackers to use … wordfence
a0c74807-b85c-478e-bebf-1f0b46a21c11
< 2.4.3
MEDIUM 4.3 The Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-Click Import for … wordfence
a0c68bb6-77a2-4232-923a-37f2c0327743 MEDIUM 4.3 The SMS for Lead Capture Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … wordfence
a0c2ba36-8eb0-4a49-9304-2922f248a89d
< 6.15.13
MEDIUM 4.3 The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
a0c14e4e-9437-4e98-b720-72d6aab9e05f MEDIUM 4.3 The Business Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
a08e4147-9a57-4936-9a18-02110c79a8bb MEDIUM 4.3 The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
a07df12c-375d-4a98-b5f6-aa14cfd432a4
< 7.0.7
MEDIUM 4.3 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Payment Bypass in all vers… wordfence
a077e95f-7912-4b94-89f3-54f37adfcd8e
< 3.25
MEDIUM 4.3 The WebwinkelKeur plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2… wordfence
← Prev 1429 1430 1431 1432 1433 1434 1435 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top