πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1434 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9f35a407-a7dd-4b6b-8c77-9a20ba797429
< 4.0.11
MEDIUM 4.3 The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress … wordfence
9f34a917-1c96-4f2a-b496-8ff848cdc314
< 4.1.4
MEDIUM 4.3 The Elementor Website Builder – more than just a page builder plugin for WordPress is vulnerable to Sensitive Informat… wordfence
9f19030c-bee2-4d04-a45f-517783cece5e
< 4.0.1
MEDIUM 4.3 The JCH Optimize plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
9f1902e7-66e9-417f-97ba-4db766cf29f1 MEDIUM 4.3 The Sunny Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… wordfence
9f1078b8-f458-46a6-9982-e8d2d1d1b73b
< 3.12.3
MEDIUM 4.3 The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t… wordfence
9f0cc8da-5377-4e1a-85d0-d8b6f314818f
< 2.2.0
MEDIUM 4.3 The Term Order plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.0.… wordfence
9effc186-c225-4b3b-9b8c-c453505a41de
< 1.3.7.3
MEDIUM 4.3 The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object … wordfence
9efea864-544d-4c13-a5a8-68d21ce6f762 MEDIUM 4.3 The Litho Addons plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
9efc782a-ec61-4741-81fd-a263a2739e16
< 4.0.7
MEDIUM 4.3 The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability… wordfence
9efb88e2-381f-4e26-80bb-1b034ffc1c91
< 1.0.26
MEDIUM 4.3 The Table & Contact Form 7 Database – Tablesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… wordfence
9efa43c6-1ec9-4380-9c53-eca47cdc9ec9 MEDIUM 4.3 The User Profile Meta Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
9eef053c-16a1-4624-8393-08e78b221d4f
< 9.18
MEDIUM 4.3 The WP Spell Check plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
9ee26828-fa3c-4014-bcf0-8e262c39a5dc MEDIUM 4.3 The Raychat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.1. Th… wordfence
9ed9c59c-191f-4219-8701-ce2f088b3b6d
< 2.6.94
MEDIUM 4.3 The Smart Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
9ed24d24-e899-4850-8552-4f6cf45fa467
< 3.1.0
MEDIUM 4.3 The Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist plugin for WordPress is vulnerable to Sensiti… wordfence
9ed0d4b6-f553-4aa5-9dfa-49df78f4269d
< 3.6.16
MEDIUM 4.3 The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordP… wordfence
9ecd4231-d1b7-420e-a8af-1508fed11d1f
< 8.5.5
MEDIUM 4.3 The WP VR plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
9ebeba9e-bda9-4cdd-bb59-fd7265f49c50
< 1.3.4
MEDIUM 4.3 The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to Insecur… wordfence
9ea49a07-022e-4c9a-b1d3-ff900b337067
< 1.1.6
MEDIUM 4.3 The AffiEasy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. T… wordfence
9ea2dfc5-0dcc-4ea1-9ade-d59021e078fa
< 1.3.7.4
MEDIUM 4.3 The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object … wordfence
9e9a5b7e-db74-4c66-a659-85b2509fded4
< 2.9.12
MEDIUM 4.3 The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of d… wordfence
9e932f7a-7012-499c-922f-29ed567d4bc4
< 2.6.6
MEDIUM 4.3 The WPSpeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.5… wordfence
9e6eec31-0603-40ab-9ed1-eedb163de1d6 MEDIUM 4.3 The Misiek Photo Album plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
9e4a1671-56aa-4003-bed7-b793d14522d7
< 17.6
MEDIUM 4.3 The WP Google Review Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
9e45feb6-5ffa-4ad3-9549-4414988f040e
< 3.2
MEDIUM 4.3 The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… wordfence
← Prev 1431 1432 1433 1434 1435 1436 1437 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top