πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1442 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
97344674-15df-45e6-9906-f21a9920a6e1 MEDIUM 4.3 The Foyer – Digital Signage for WordPress plugin for WordPress is vulnerable to unauthorized content injection due to … wordfence
9731a6bc-18f4-42cc-862b-f098251228ef
< 3.0.4
MEDIUM 4.3 The EasyMe Connect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
97312cf2-dcff-466f-a27c-25686216ed04
< 4.0.28
MEDIUM 4.3 The Church Admin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.… wordfence
972ce9b3-93f6-449d-8d3e-79cfaffa082d MEDIUM 4.3 The AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One plugin for WordPress is vulnerabl… wordfence
972be091-64c4-4cb7-9563-70249c0db157
< 2.1.13
MEDIUM 4.3 The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability c… wordfence
9726b59e-4826-4253-889c-686763ad3689
< 3.1.3
MEDIUM 4.3 The Hestia theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.2. This… wordfence
970b3a0f-c1cc-4d85-8271-a523ccdbcc39
< 5.1.1
MEDIUM 4.3 The Analytify Dashboard plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… wordfence
9705d293-ea89-46dc-95f5-15ff0f9c8d1e
< 2.8.1
MEDIUM 4.3 The Brizy Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8… wordfence
96fa9ed7-6c13-4356-8a25-8a309be2b0e9
< 3.24.6
MEDIUM 4.3 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information … wordfence
96f77fdc-4e91-43c0-8bc6-7bb202945c7d
< 10.2.3
MEDIUM 4.3 The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2 … wordfence
96deac16-cb64-4246-b8d0-05a020142f1d MEDIUM 4.3 The Ovic Addon Toolkit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
96cfd09d-2238-43aa-917c-94f418cc91ce MEDIUM 4.3 The SoundCloud Ultimate Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
969a9357-47ce-4c7e-a259-559a2584485a
< 3.5.8
MEDIUM 4.3 The Linet ERP-Woocommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
9699970f-76a4-4f10-9836-4e46ac8d6914
< 3.1.14
MEDIUM 4.3 The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to unauthorized access due to a missin… wordfence
968920b9-febf-4d76-a16b-f27954cd72e5
< 3.7.2
MEDIUM 4.3 The Custom 404 Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.… wordfence
9686e2ab-3328-43d6-bc70-b61555cb3791
< 2.2.4
MEDIUM 4.3 The Smart Coupons For WooCommerce Coupons plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
96850eb6-77d8-4012-b360-a417918cab0e
< 2.28.15
MEDIUM 4.3 The Seraphinite Accelerator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
966523a4-3d4b-444b-b9d0-63c72527a99f
< 3.1.0
MEDIUM 4.3 The WP Login and Register using JWT plugin for WordPress is vulnerable to unauthorized access of data due to a missing c… wordfence
966159e8-e393-4eba-a8cd-8f343762b0b8
< 3.19
MEDIUM 4.3 The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
965bb0f7-0757-4842-9c26-a5574145a6a3 MEDIUM 4.3 The Video Blogster Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
965b6a19-3e5f-446c-a739-746e886a5585 MEDIUM 4.3 The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
964950dc-d8e1-4a9b-bef2-ea51abc5a925 MEDIUM 4.3 The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing nonce check on t… wordfence
9634fbea-7562-43c4-bde9-03e762ce01a1
< 1.1.6
MEDIUM 4.3 The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulne… wordfence
962ca39f-dec5-4881-aeb7-7cdfa607af31
< 1.8.6
MEDIUM 4.3 The 3D viewer – Embed 3D Models plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
961f4a7d-ca95-4c2c-8355-9d1d65cb614d
< 2.1.2
MEDIUM 4.3 The WebToffee eCommerce Marketing Automation – Email marketing, Popups, Email customizer plugin for WordPress is vulne… wordfence
← Prev 1439 1440 1441 1442 1443 1444 1445 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top