πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1436 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9cbbbb51-d770-429a-8256-c83ad71560ba MEDIUM 4.3 The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
9cac5c66-d366-4a67-b29b-4efed67ab55b
< 2.3.5
MEDIUM 4.3 The wpForo Forum plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu… wordfence
9ca8e4ca-0ddf-492a-99c0-158ebdd7f86f MEDIUM 4.3 The Smart Online Order for Clover plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
9c9b6214-8109-4b7e-8075-e6fce5ea11ad MEDIUM 4.3 The Free Woocommerce Product Table View – Woo Table Pro plugin for WordPress is vulnerable to unauthorized access due … wordfence
9c935ec2-c51e-4760-bccc-3a6988bd4262 MEDIUM 4.3 The Change default login logo,url and title plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
9c90eb14-7f57-4d14-b485-7eb4a7fa6770 MEDIUM 4.3 The Cincopa video and media plug-in plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions… wordfence
9c865d60-9e9f-450a-a3c4-43d991bf2478
< 1.10
MEDIUM 4.3 The WordPress Exit Box Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
9c6f9a3d-54a6-4405-b42b-37fc8342af96
< 4.1.2
MEDIUM 4.3 The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to m… wordfence
9c6b747e-d267-4fd3-a4fd-022aa657c796
< 3.1.22
MEDIUM 4.3 The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
9c53faf5-a6a6-4eb9-ad82-31873c0a6282
< 8.46.0
MEDIUM 4.3 The Smart Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
9c4b2568-11b3-4fd8-a270-0ab4a29b3055 MEDIUM 4.3 The Javo Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.0.2… wordfence
9c3a047f-be12-4308-a4a5-fbbbc37f674d
< 1.4.8
MEDIUM 4.3 The WP Reroute Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
9c2c11a3-ef42-4587-aea1-aa8f70b85953
< 6.1.3
MEDIUM 4.3 The Float menu – awesome floating side menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve… wordfence
9c26a76d-a104-4ea6-be9f-9e8dfc3b5cd5 MEDIUM 4.3 The WP Admin Microblog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
9c06e0a9-a13a-4cee-a1a5-c43c114b2dbf
< 3.6.2
MEDIUM 4.3 The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Missing Authorization in all versions u… wordfence
9bff2532-802c-4bb1-a0a2-7f5f928deb23
< 1.2.0
MEDIUM 4.3 The Coinbase Commerce for Contact Form 7 plugin for WordPress is vulnerable to Missing Authorization in versions up to a… wordfence
9bf94803-1ddf-4b9b-9624-497db455aab2 MEDIUM 4.3 The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil… wordfence
9bf771b7-6c94-4c4e-8a89-5300f21aad4d
< 2.0.1
MEDIUM 4.3 The Kevin's Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
9be389b4-0f76-4f58-806e-dfba531934ea
< 4.5.9
MEDIUM 4.3 The MDirector Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
9bd8c4e5-ef53-47e8-8658-291509e9b987 MEDIUM 4.3 The Easy Call Now by ThikShare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
9bd04f78-0b9c-4985-b450-007bb5cc9e26
< 1.3.0
MEDIUM 4.3 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… wordfence
9bcbc0cf-69e5-4d6e-8987-a0fbbaf41740
< 8.5.42
MEDIUM 4.3 The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to unauthorize… wordfence
9bc3c8c4-9f56-467b-a772-743f007d6bef
< 1.2.40
MEDIUM 4.3 The WP Time Slots Booking Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
9bbd9ea4-8b5b-4497-a178-94eaec0b8211 MEDIUM 4.3 The Overton theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, … wordfence
9bbd528a-94fe-4979-b30f-02c6872db086
< 2.10.4
MEDIUM 4.3 The Simple Job Board plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
← Prev 1433 1434 1435 1436 1437 1438 1439 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top