πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1433 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a063fab3-6d52-4f2a-b51f-b76fa2d4711c MEDIUM 4.3 The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized modif… wordfence
a06147c7-a96e-4f12-9a67-23ca82b09942 MEDIUM 4.3 The Ovic Responsive WPBakery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
a055e6ca-6ef0-4c40-80f4-14a5a19a6db6
< 3.0.0
MEDIUM 4.3 The Double the Donation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
a04db024-5198-490f-bf5f-d5bad1b21ce4 MEDIUM 4.3 The Zegen - Church WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
a04870e0-41c8-464b-b30e-0bf7900e1433
< 4.2.3
MEDIUM 4.3 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticat… wordfence
a033ea44-8084-44c1-8e24-bdb1b61c3566
< 1.5.0
MEDIUM 4.3 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of d… wordfence
a0320c16-de32-484f-b17c-5acf0144a373
< 1.3.2
MEDIUM 4.3 The Custom WooCommerce Checkout Fields Editor plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
a023cdc5-3814-4120-86b2-6a60d385f898
< 4.6.0.4
MEDIUM 4.3 The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) t… wordfence
a016b6b3-3a3f-4f25-9207-2460798044f0
< 2.0.5
MEDIUM 4.3 The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server inform… wordfence
a00997d4-f242-4d49-8542-0738efa66222
< 5.7.9
MEDIUM 4.3 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization… wordfence
9ffb0980-75f8-4f6b-a0ed-2f65bc5aa103 MEDIUM 4.3 The Admin in English with Switch plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
9febd85f-a063-4ee5-8481-0d97133157d0 MEDIUM 4.3 The Simple Sticky Add To Cart For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
9fe7fca1-9e6e-48b5-9818-793fe1045334
< 2.268
MEDIUM 4.3 The Ashe theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in ver… wordfence
9fd15c0b-cd3b-45e7-8379-b0e64e64d6b1
< 5.2.4
MEDIUM 4.3 The Herd Effects for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.3. This… wordfence
9fb4ad52-a0b2-4645-bf0d-132b4ce8a0a1
< 1.9.1
MEDIUM 4.3 The TextMe SMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
9fa82247-8f24-433d-993b-0a0465a32c6b MEDIUM 4.3 The Did Prestashop Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
9fa0a652-f5d1-4671-a9c1-21e6fd1ad46c
< 6.6.3
MEDIUM 4.3 The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
9f9d6da5-1598-4df4-8efc-306370446443 MEDIUM 4.3 The ZT Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
9f98cdc5-813b-4ed0-98be-c288c1654087 MEDIUM 4.3 The UnGrabber plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
9f8c5853-6e21-4a70-a547-e3f0f4b1d7d0
< 1.0.3
MEDIUM 4.3 The Caret Country Access Limit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
9f8b1103-71b2-421e-bcbe-f2716b59e367 MEDIUM 4.3 The Gallery Metabox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
9f8568f2-a33e-4e05-b26b-fbaea37e2c2c
< 4.5.2
MEDIUM 4.3 The EduMall - Professional LMS Education Center WordPress Theme theme for WordPress is vulnerable to unauthorized access… wordfence
9f65baee-11fa-4592-9170-5057faee544e
< 10.6.6
MEDIUM 4.3 The Wp EMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10… wordfence
9f49e727-cac4-4a46-b649-5ca48d5e2402
< 1.5
MEDIUM 4.3 The Add Any Extension to Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
9f3619d9-7572-439e-a284-d59ef5de08f3 MEDIUM 4.3 The Takeads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.13. Thi… wordfence
← Prev 1430 1431 1432 1433 1434 1435 1436 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top