πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1443 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
961d6d1d-46e8-489f-ac5f-51b55c5a0460
< 2.0.6
MEDIUM 4.3 The DX Delete Attached Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
961b9872-e602-49a7-a11a-566f3cd4bd0a
< 3.33.0
MEDIUM 4.3 The WishList Member X plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
9611b4ba-0946-4180-a51d-18fcba84661e
< 2.13.3
MEDIUM 4.3 The Newspack Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
9603e394-b358-4599-8610-ef5737a39de0
< 3.11.0
MEDIUM 4.3 The FunnelKit Checkout plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… wordfence
9601932a-0e0d-408f-91d0-47ff4e726b23
< 4.4.7
MEDIUM 4.3 The Event Booking Manager for WooCommerce – WpEvently plugin for WordPress is vulnerable to unauthorized access due to… wordfence
95f6e5cd-e153-419b-86f6-ce5c73d73738 MEDIUM 4.3 The db-access plugin for WordPress is vulnerable to SQL Injection via the 'key' parameter in all versions up to, and inc… wordfence
95f5b4df-5214-4f36-8dd5-a1a816fbc3db
< 2.1.7
MEDIUM 4.3 The Perfmatters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
95f49080-2263-4f6d-9372-30137efd8e10
< 2.0.20
MEDIUM 4.3 The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of da… wordfence
95e79929-332f-42bc-b2ad-00b8867dcb86
< 1.0.8
MEDIUM 4.3 The TrueBooker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.7.… wordfence
95de9099-6071-46d8-a7c9-bb2c1caa6b38
< 1.9.2.3
MEDIUM 4.3 The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress i… wordfence
95da08b2-e26a-4323-89ad-7f9d870e0186 MEDIUM 4.3 The WP-CalDav2ICS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3… wordfence
95d9995a-d99e-4136-84f9-1d3dfc4a4bf0
< 3.2.0
MEDIUM 4.3 The myCred plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
95c5a219-0b04-424c-a3dd-d705b1b41ddc MEDIUM 4.3 The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. … wordfence
95b82437-e63c-4762-9193-40ea74dbf1c9
< 1.2.2
MEDIUM 4.3 The Usermaven plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2… wordfence
95b3a3bb-8b64-4659-a4cd-b0109d1b572d
< 2.1.4.4
MEDIUM 4.3 The InPost Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
95ae7cb4-3434-4c75-a803-81ae96ba5891
< 4.4.4
MEDIUM 4.3 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensiti… wordfence
95ad0139-eb12-4c02-95fb-cd19b6a6ab02
< 1.2.4
MEDIUM 4.3 The Health Check & Troubleshooting plugin for WordPress is vulnerable to Path Traversal in versions up to, and including… wordfence
95986a4d-94fb-4afe-ba1e-382d6f4c550f
< 2.1.0.14
MEDIUM 4.3 The WP Inventory Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
9596cae1-37d8-4618-a701-34e8461c3d73 MEDIUM 4.3 The WordPress StoryMap Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
9596c243-4099-420a-aa2a-381b6299f927
< 1.3.32
MEDIUM 4.3 The Contact Form Email for WordPress is vulnerable to unauthorized feedback submission due to a missing capability check… wordfence
959608e2-7745-403c-953e-4b5d73062f47
< 2.20.0
MEDIUM 4.3 The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to 2.20.0… wordfence
957fde11-9dec-4d68-813c-2f6f4973900e MEDIUM 4.3 The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
95723482-a6c5-4e95-a88d-c50a88108715
< 1.2.8
MEDIUM 4.3 The HT Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.7. Th… wordfence
956fa041-1a48-4a88-a78b-a1617540d6dc
< 1.1.9
MEDIUM 4.3 The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized… wordfence
956984d4-4f8b-4e20-8002-4e9809b3872c MEDIUM 4.3 The Page Restrict plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
← Prev 1440 1441 1442 1443 1444 1445 1446 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top