πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1437 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9bbabf5e-dbfc-4b01-94ae-0e8fd6b3cc26
< 1.2.0
MEDIUM 4.3 The Bold Timeline Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a logic error on t… wordfence
9bb3c2a9-3307-422d-83b5-a2fe16b7f2bb
< 1.10.1
MEDIUM 4.3 The WP YouTube Live plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
9ba40bde-7926-4aa5-a282-8543aea23381
< 3.2
MEDIUM 4.3 The Meta Tag Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
9b8dc6f3-0ffc-4317-a32f-14dd7c301d30
< 1.4.3
MEDIUM 4.3 The Legal Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.2… wordfence
9b86d26e-cda0-4558-9967-3ec6f5eff510
< 2.13.7
MEDIUM 4.3 The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in al… wordfence
9b7c3932-a52f-468d-af4e-e8bd53b14a1b
< 2.2.1
MEDIUM 4.3 The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
9b5952d1-e3ee-430c-a200-0c5bb551a100
< 3.1.2
MEDIUM 4.3 The Button Generator – easily Button Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… wordfence
9b4b517c-d605-4370-ae12-7c198c82b1d9
< 4.0.1
MEDIUM 4.3 The Mini Cart Drawer For WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing … wordfence
9b3c7359-4de3-485f-b1b4-9e83b95c7f7c
< 2.15.8
MEDIUM 4.3 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
9b343533-8690-4167-8de8-7be2d2b2e44a MEDIUM 4.3 The Get Better Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
9b2ab63d-1fd5-4de5-9c77-e704cde887c9
< 1.6.0
MEDIUM 4.3 The Post to Social Media – WordPress to Hootsuite plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
9b2a9f5c-c9a0-4366-91ea-bec7839e951f MEDIUM 4.3 The Hide Real Download Path plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
9b28924e-8d4b-4eb4-8564-10bde2c82d69
< 6.3.4
MEDIUM 4.3 The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized acces… wordfence
9b27cf00-bc1f-4c91-b5ee-debba9f361ed MEDIUM 4.3 The Werkstatt - Creative Portfolio WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a mis… wordfence
9b203694-e18a-4262-bf58-f1dcd0358890 MEDIUM 4.3 The WP Blogs' Planetarium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
9b0b6433-5651-4a9d-8356-5d02d51830f4 MEDIUM 4.3 The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a… wordfence
9b09f4de-f67d-4d15-a3e3-0cc78cfe7fe8 MEDIUM 4.3 The Advanced What should we write next about plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
9b09338c-a28f-4950-b0c1-98ab85e58c0a
< 2.0.8
MEDIUM 4.3 The Optimize images ALT Text plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
9b0737b6-c30b-4244-bf17-4ade1991af6a MEDIUM 4.3 The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere … wordfence
9af6c319-7660-4368-b2f8-1ed1d01ee73a
< 1.31.2.0
MEDIUM 4.3 The VK Block Patterns plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
9af36edd-4520-4afc-8d3a-c9a96659ddf8
< 8.1.0
MEDIUM 4.3 The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
9ae63e7d-c5a2-4e8d-96e8-5d3c9c9ea1bf MEDIUM 4.3 The Gallery Images Ape plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when… wordfence
9adf94ac-30ef-4c24-afa6-04248c25bd7f
< 2.4.17
MEDIUM 4.3 The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in … wordfence
9acc923b-f2c6-4fac-a75d-6097286fb9ae
< 1.0.8
MEDIUM 4.3 The Product Author for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
9ab380db-5c5e-4185-8da1-8e0f0363bbcf
< 3.8.3.3
MEDIUM 4.3 The Pie Register Premium plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
← Prev 1434 1435 1436 1437 1438 1439 1440 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top