πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1435 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9e44d85d-6bde-4194-8f33-5db6dacf544c
< 3.4.4
MEDIUM 4.3 The TinyPNG plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.3. Th… wordfence
9e3e009d-85bc-4ed3-a298-fa1484cb4694
< 4.2.6
MEDIUM 4.3 The Primer MyData for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
9e11e1b5-dbba-4920-a65c-210600878861 MEDIUM 4.3 The Video XML Sitemap Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
9df827b1-e42f-4957-b59c-f6d6a9d997a8 MEDIUM 4.3 The Wishlist plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, … wordfence
9dbfa5b6-9d8a-4874-8586-0581272ccc40
< 1.5.6
MEDIUM 4.3 The Duplicate Post plugin for WordPress is vulnerable to unauthorized access in all versions up to 1.5.6. This is due to… wordfence
9dbdb6cc-2a00-4d34-9c11-62f3d1b51c73
< 1.2.3
MEDIUM 4.3 The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is vulnerable to Information Exposure in al… wordfence
9dbb5ce8-0afb-43f5-93b6-0b11939f4a93
< 1.8.8
MEDIUM 4.3 The Faust.js plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
9da6adf9-7219-4766-8cad-b8fff230a5e9
< 2.6.30
MEDIUM 4.3 The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized ac… wordfence
9d98946e-864f-434e-8f45-85d663bbefee MEDIUM 4.3 The Just Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
9d986739-d6a5-491d-948f-4c58af75369a
< 1.5.3
MEDIUM 4.3 The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
9d821dd2-ce97-4240-b5d6-f6e974a681a3 MEDIUM 4.3 The Dolcino - Pastry and Cake Shop WordPress Theme theme for WordPress is vulnerable to Insecure Direct Object Reference… wordfence
9d7838c8-938f-487a-9120-4cb13f0e6f6b
< 1.0.271.1
MEDIUM 4.3 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access du… wordfence
9d691974-6876-44f2-93a3-64f568bbebeb
< 5.1.1
MEDIUM 4.3 The Min Max Step Quantity Limits Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forger… wordfence
9d682596-c32d-4abd-ba39-b57fc45c9ce0 MEDIUM 4.3 The Qtranslate Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
9d64d711-f2d9-4447-9ac1-80c5ea51c23e MEDIUM 4.3 The Plugin Name: Device Theme Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
9d619314-88c2-4c42-863d-46f99a4aaa73 MEDIUM 4.3 The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
9d3ca31a-a21f-4e38-91bb-5fabdb4440a5 MEDIUM 4.3 The Donate visa plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
9d32bda7-2d2d-4364-8ac9-e32950f889ed
< 4.10.2
MEDIUM 4.3 The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 4.10.2 (exclusive)… wordfence
9d2345d2-0bcf-46fc-a857-0ec10a1b1c26
< 3.1.5
MEDIUM 4.3 The XCloner plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.1.4 via le… wordfence
9d11c022-9938-4a9e-be16-db986fdfa1c8 MEDIUM 4.3 The Youtube SpeedLoad plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
9cff616c-fd2e-4c92-a284-87ce38e45934 MEDIUM 4.3 The RSS Digest plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
9cedd6bc-4629-46e1-998b-3713025ab428 MEDIUM 4.3 The AdMail – Multilingual Back in-Stock Notifier for WooCommerce plugin for WordPress is vulnerable to unauthorized ac… wordfence
9cec5880-214b-4a35-9b36-e3a9e54e8f3b
< 3.31.7
MEDIUM 4.3 The Leyka plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ley… wordfence
9ce8ad5f-05e8-4279-915a-1c94559d4e56 MEDIUM 4.3 The Advanced Flamingo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
9cbce69a-53d0-4b83-9b7a-893a6b9c39c4
< 2.2.7
MEDIUM 4.3 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
← Prev 1432 1433 1434 1435 1436 1437 1438 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top