πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1441 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
98358366-7cb0-40ae-a931-10985c916af1
< 1.1.10
MEDIUM 4.3 The Potent Donations for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
982b23c5-2414-48f7-a2f5-96fef54f8d69
< 3.3.2
MEDIUM 4.3 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification … wordfence
981c9cd8-9765-405e-b53f-be7c6f839764
< 2.0.3
MEDIUM 4.3 The UPC/EAN/GTIN Barcode Generator/Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
981908d3-e1e7-4093-a2ee-69aa50127731
< 1.7.0
MEDIUM 4.3 The Custom Order Numbers for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
980c1f30-0877-4437-aff8-6d5235b6a4d6 MEDIUM 4.3 The i-amaze theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.7. Thi… wordfence
98053141-fe97-4bd4-b820-b6cca3426109
< 4.4.2
MEDIUM 4.3 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress … wordfence
97f96f18-3296-4e9b-adae-a073da520778
< 1.79.262
MEDIUM 4.3 The WP Fast Total Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
97d78b4b-568e-43e7-bebf-091179c321f6
< 3.6.4
MEDIUM 4.3 The Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable… wordfence
97d5007f-1786-4a36-a3d2-b536bec31a29
< 1.5.0
MEDIUM 4.3 The Product Configurator for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
97d305b8-0454-4407-8fed-7884c4b19d8e
< 1.4.0
MEDIUM 4.3 The FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler plugin for WordPress is vulnerable to unauthorize… wordfence
97d28ec3-a06a-4f8b-9926-f81166be324d
< 5.11.1
MEDIUM 4.3 The WPJobBoard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 5.11.1. This is due to… wordfence
97ced4ed-915b-4234-b59d-75db983f90e8
< 2.6.1
MEDIUM 4.3 The Ultimate Member plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
97c8858a-f05d-4159-b914-4e6ae9bf0d79 MEDIUM 4.3 The Custom Options Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
97925dfe-76f6-4214-930d-aafd4caec42e
< 2.4.6
MEDIUM 4.3 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Sensitive Information … wordfence
9790c592-1445-4f9d-987e-ae5ab49c4dcd
< 1.7.9
MEDIUM 4.3 The WP-CFM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.8.… wordfence
979001c4-45dd-4168-8749-c8eebe237b60
< 1.3
MEDIUM 4.3 The wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions plugin for WordPress is vulnerable to authoriza… wordfence
978d5715-7993-4f89-8d69-895467633bfb
< 4.5.4
MEDIUM 4.3 The WP Meta SEO plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on t… wordfence
978850f0-c498-40a7-aab5-22afc7e97824
< 2.4.10
MEDIUM 4.3 The Bulk Page Generator – LPagery plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
9781b2bf-464c-4ff6-87d1-6c38acbd457c MEDIUM 4.3 The Namaste! LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
977e407c-0650-454f-98bd-b39bb8c8c61f
< 1.3.3
MEDIUM 4.3 The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPres… wordfence
9759e1f0-e134-4c7f-88aa-63dbae7067f1
< 1.0.249
MEDIUM 4.3 The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
97548879-f015-4adc-8a84-535d210ae0de MEDIUM 4.3 The Preloader Matrix plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
975487bf-5e62-47e7-8112-5cd91f9c9483
< 1.2.1
MEDIUM 4.3 The Perfect Portfolio theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
974ffc87-369a-431e-b601-8c6679d963c3 MEDIUM 4.3 The zStore Manager Basic plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability che… wordfence
974c0e94-8d09-488a-9a09-49f0b9ce112c
< 6.4.0.1
MEDIUM 4.3 Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access of data due to a insufficient capabil… wordfence
← Prev 1438 1439 1440 1441 1442 1443 1444 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top