πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1440 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9921f4d0-0aa2-457e-afb2-7ecafb605948
< 2.1.38
MEDIUM 4.3 The Blocksy Companion Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi… wordfence
9916af89-4b12-47eb-adb2-56267f077d2f
< 2.2.2
MEDIUM 4.3 Multiple plugins for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is due to missing … wordfence
9915758a-47f0-4fa7-8885-311b2f75a7b6 MEDIUM 4.3 The Holmes - Digital Agency WordPress Theme theme for WordPress is vulnerable to Insecure Direct Object Reference in all… wordfence
98ebcc70-58c3-4c9d-a1cd-776c159647ed MEDIUM 4.3 The WP Tabs Slides plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
98e82ea8-3d92-4ce3-a280-2def3ab5430f
< 6.1.2
MEDIUM 4.3 The MainWP Dashboard: Self-hosted WordPress Management for Agencies plugin for WordPress is vulnerable to unauthorized a… wordfence
98e0d103-2369-4c6a-93ae-6be2a1770bae
< 1.3.13
MEDIUM 4.3 The Dynamics 365 Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
98dffc17-ac45-4ccd-ae57-96b36bd02be3
< 1.0.7.1
MEDIUM 4.3 The WOLF plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.7. This … wordfence
98bbec12-25f5-429c-a926-e8da34945962
< 3.35.6
MEDIUM 4.3 The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
98b38844-c6fe-4655-8bbe-7600203b567e
< 1.6.5
MEDIUM 4.3 The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi… wordfence
98ae3315-8361-43bb-be2c-1564f4df8d5b
< 3.98.8
MEDIUM 4.3 The Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9… wordfence
98a953b9-60e1-4445-a61e-88d5867895eb
< 1.27.10
MEDIUM 4.3 The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to unauthorized… wordfence
98a73a02-33fa-4dd4-9606-3d35d58c2398
< 3.3.101
MEDIUM 4.3 The Zephyr Project Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,… wordfence
98a734d2-ea6f-4053-94b5-d20d6418b3ae
< 3.4.3
MEDIUM 4.3 The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2.… wordfence
98a2570c-c757-44ad-9981-af0bf2d3c341
< 2.0.2
MEDIUM 4.3 The WP Job Portal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0… wordfence
989f312b-9c6c-44e1-9c4c-03917c8ec296
< 2.3.2
MEDIUM 4.3 The Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This … wordfence
989836fc-a15d-4424-be0e-348e1acc7466
< 1.7.0
MEDIUM 4.3 The WP Like Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
9891587b-2a63-41be-b79d-afe407dd57fa
< 1.3
MEDIUM 4.3 The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versio… wordfence
9879150f-ea35-4b05-af67-06f82714c430
< 5.2.4
MEDIUM 4.3 The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable … wordfence
98736b9d-3e0a-40c0-900a-fbbaaac07958 MEDIUM 4.3 The TITLE ANIMATOR plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
98730677-200b-4b1a-8568-7af8b2b0e94b
< 2.0.4
MEDIUM 4.3 The Welcome Bar for WordPress is vulnerable to unauthorized AJAX action access due to a missing capability check on the … wordfence
9870db7f-0c8e-44a4-aa0f-13709d773756
< 2.10.1
MEDIUM 4.3 The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.… wordfence
986835a7-2f73-4139-b080-ca1f7af077fb MEDIUM 4.3 The Brilliant Web-to-Lead for Salesforce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
985dfe25-4860-477a-bd85-5bf3375b86db
< 2.36
MEDIUM 4.3 The Post Duplicator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
9854d09a-2fab-46e6-9fc1-ff6d68df2662
< 2.3.11
MEDIUM 4.3 The Request a Quote plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
9852e499-f413-4218-9bac-6c2be62ecc32 MEDIUM 4.3 The DW Question & Answer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
← Prev 1437 1438 1439 1440 1441 1442 1443 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top