πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1439 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
99bc930e-8232-4c8e-b6c0-982650c7f407 MEDIUM 4.3 The Image Cleanup plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
99b3309d-be3f-427a-883f-8d3d47e141fe MEDIUM 4.3 The Entrada theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.7.7.… wordfence
99a21d91-e17a-400e-9013-c074e76bbf6e
< 16.26.6
MEDIUM 4.3 The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Insecure Direct Object Re… wordfence
9999301a-002d-441b-bd66-6b7f4c46a8bf
< 2.2.9
MEDIUM 4.3 The Sign-up Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
99984fff-94e3-46fb-8241-88fcda556054
< 2.11.0
MEDIUM 4.3 The Stock Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
9993d84e-7337-4eda-af3c-039b6d8c8fe6 MEDIUM 4.3 The Broken Link Checker for YouTube plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
9992c6ac-8e29-4c99-8439-663cc7c190b9
< 0.7.1
MEDIUM 4.3 The Brave Popup Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
998e545c-2ad5-48ec-bad1-d346170af408
< 5.0.4
MEDIUM 4.3 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for Word… wordfence
997e5fdb-cece-4850-a0e4-49343d9c415d
< 2.11
MEDIUM 4.3 The Web Accessibility By accessiBe plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
9978a072-9f6c-4fa2-b414-b18e0c10ee61
< 6.0.4
MEDIUM 4.3 The MotoPress Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … wordfence
996e0432-e795-4c01-8182-603a47f4f341 MEDIUM 4.3 The WP Firebase Push Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
996dc1d7-12f8-467d-bf48-a7a82f1c0a41
< 3.8.2.3
MEDIUM 4.3 The Brands for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
996d1514-2c1f-4888-ac2f-bc58e926d3ef
< 3.8.4
MEDIUM 4.3 The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due t… wordfence
996c7433-dd82-4216-86b9-005f43c06c3a
< 1.4.5
MEDIUM 4.3 The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to unauthorized modification… wordfence
996c2843-158c-475a-874e-c5af00347d8c
< 10.0.2
MEDIUM 4.3 The PixelYourSite – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
996b2671-be25-4821-b0b8-b88f0ed112bc
< 3.8.1
MEDIUM 4.3 The Academy LMS plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includ… wordfence
99656d69-6fb6-45d6-bd62-9849e5dead7b
< 1.0.1
MEDIUM 4.3 The Tours plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in a… wordfence
995ce1f8-dee8-418b-bcdc-5e5915bfc848
< 1.3.6
MEDIUM 4.3 The Calculate Prices based on Distance For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to … wordfence
995a086a-4795-4092-823c-b941445dc361
< 7.1.3
MEDIUM 4.3 The Booster Elite for WooCommerce plugin for WordPress is vulnerable to content injection via an unknown parameter in al… wordfence
9958d7d7-ddeb-42f4-a5bd-6dd55ec9b6e0
< 0.4.8
MEDIUM 4.3 The GTmetrix for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
99489cc0-2e73-4d55-b95f-46d574897fac
< 3.3.2
MEDIUM 4.3 The WooCommerce Etsy Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
99467820-9caf-466c-8421-d6521699e6d6
< 3.12.6
MEDIUM 4.3 The Email Marketing Plugin – WP Email Capture plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … wordfence
99304234-101d-408b-b463-67b8e2c8f679
< 2.2.1
MEDIUM 4.3 The Live Shopping & Shoppable Videos For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
992fc98f-4b23-4596-81fb-5543d82fd615
< 3.4.2
MEDIUM 4.3 The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
992abd72-2a8e-4bda-94c2-4a7f88487906
< 2.7.5
MEDIUM 4.3 The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. … wordfence
← Prev 1436 1437 1438 1439 1440 1441 1442 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top