πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1444 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9567f199-7c31-4df3-aa2c-911780b2497a
< 1.3.8
MEDIUM 4.3 The Portfolio and Projects plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
955d2b8d-af39-43f9-a513-7cc421cbd4b5
< 1.5.2
MEDIUM 4.3 The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to unauthorized acce… wordfence
955d0aa2-bf57-4df7-a2d3-0a4ade4fc50f
< 2.1.2
MEDIUM 4.3 The Fluent Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including… wordfence
955b7d69-7921-4c79-9443-c494f5bba57d
< 4.1.4
MEDIUM 4.3 The Houzez Theme - Functionality plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
95550fd3-13e5-4341-8551-efe9070b0ada MEDIUM 4.3 The WP Discord Post Plus – Supports Unlimited Channels plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
9540b339-3386-4ee8-8141-acb9f3d83772
< 2.9.2
MEDIUM 4.3 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in al… wordfence
953f4838-d0d5-4546-ac97-c1b442236c5d MEDIUM 4.3 The Frontpage Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
9528d0d8-9f56-43e4-9b86-92e54ea38013
< 1.0.8
MEDIUM 4.3 The Coachify theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.7. Th… wordfence
951e4651-56d6-474d-84b3-5a7cfc357b9f MEDIUM 4.3 The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the … wordfence
9503f908-ead2-4c34-89b9-1e2348b90f3c MEDIUM 4.3 The Set Bulk Post Categories plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
94f0aa43-3d36-4e02-8d96-5d0a2bd8dbd9 MEDIUM 4.3 The CubeWP Framework plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inclu… wordfence
94e6118a-5950-481a-92f3-f25e01f186d7
< 18.18.2
MEDIUM 4.3 The WPSSO Core – Complete and Optimized Structured Data SEO plugin for WordPress is vulnerable to unauthorized access … wordfence
94d26ec1-88e4-4bd5-89a6-692d7418df7c
< 4.06.05
MEDIUM 4.3 The WebinarIgnition plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
94b3bda3-d95b-4328-9637-b7b192d8b0e5
< 6.4.20
MEDIUM 4.3 The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Cross-Sit… wordfence
94ada60f-1e20-454e-a9d7-7849be764d81
< 3.25.11
MEDIUM 4.3 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u… wordfence
94ad6b51-ff8d-48d5-9a70-1781d13990a5
< 6.5.1
MEDIUM 4.3 The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulner… wordfence
94a18ddb-fa30-4a0f-9ce7-390dc1cee8a8 MEDIUM 4.3 The Pray For Me plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
948d3d24-f596-4ef3-936b-d68219826942
< 4.3.10
MEDIUM 4.3 The ECS – Ele Custom Skin for Elementor plugin for WordPress is vulnerable to unauthorized access in all versions up t… wordfence
948b9d68-8b31-42a0-bdc5-4a8e4e969ca9
< 3.1.4
MEDIUM 4.3 The Intuitive Custom Post Order plugin for WordPress is vulnerable to authenticated settings change in versions up to an… wordfence
94332eb8-0961-4c8d-97bb-3d5d08e8119f
< 2.1
MEDIUM 4.3 The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or … wordfence
94104431-6278-49a2-9b1a-d4ccac5f457b MEDIUM 4.3 The Frames theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
93e590f8-5f8d-4ee5-bcff-96bcb8daf4b7
< 3.0.3
MEDIUM 4.3 The BulkGate SMS Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
93e407d9-6878-4d2f-9f86-4037be95f239
< 2.0.4
MEDIUM 4.3 The Debug Log Viewer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
93db56df-d21b-4788-84b2-7b28641b5a7a MEDIUM 4.3 The LEAV Last Email Address Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions <= 1.… wordfence
93dadc33-cabf-4701-97ca-861ad90597fb
< 1.3.5
MEDIUM 4.3 The Page & Post Notes plugin for WordPress is vulnerable to unauthorized modification of notes due to a missing capabili… wordfence
← Prev 1441 1442 1443 1444 1445 1446 1447 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top