πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1445 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
93c10a58-c5f2-440b-a88e-5314143fdd90
< 6.3
MEDIUM 4.3 The WP EXtra plugin for WordPress is vulnerable to unauthorized access to restricted functionality due to a missing capa… wordfence
93b5525c-a298-420d-80cd-84cb35913981
< 4.9.2
MEDIUM 4.3 The Open Close WooCommerce Store – Best Business Schedules Manager plugin for WordPress is vulnerable to unauthorized … wordfence
93b527a8-30c0-4e47-bb2b-522380b21699
< 2.1.2
MEDIUM 4.3 The Big File Uploads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
939b408c-ae22-40ce-b500-317150a2da3b
< 5.0.11
MEDIUM 4.3 The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on th… wordfence
93800bd9-5d11-4d5b-99b2-4c5c78510af7 MEDIUM 4.3 The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data du… wordfence
937d2dac-3f07-4c0f-9f3b-c85080ba11f8 MEDIUM 4.3 The WP Church Donation plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
937d1870-a844-4033-8bc0-88e2cd9db25b
< 7.8.9
MEDIUM 4.3 The Cornerstone plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
93784c84-93b3-4f43-84a0-5aeed3ba9cfd
< 2.4
MEDIUM 4.3 The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to unauthorized access due … wordfence
9370f05a-9c69-45f4-9fd8-7017bfcf4d1e
< 1.1.121
MEDIUM 4.3 The Calculated Fields Form plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing c… wordfence
936c1b74-30ce-4be2-bb31-566fb557597e
< 1.2.9
MEDIUM 4.3 The Thim Elementor Kit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
9364c4a3-c43c-43b4-a3e3-14269ca2b928
< 1.1.4
MEDIUM 4.3 The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to … wordfence
935bf651-888e-4922-81fc-7e2e5a6fe3ba
< 2.4.2
MEDIUM 4.3 The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do n… wordfence
934d11e7-ea86-4ce8-aadd-a1739b125be0
< 4.8.4
MEDIUM 4.3 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to unaut… wordfence
934b2767-eae4-4c2d-a635-2e6a27fd9f49
< 1.4.8
MEDIUM 4.3 The Get URL Cron plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.… wordfence
934358c3-9ac6-473f-a60f-6989e0e6a145
< 20.8.8
MEDIUM 4.3 The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable… wordfence
9332f737-7620-412a-9338-1212c9c4ebd8
< 5.7.4
MEDIUM 4.3 The MyRewards plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
932d6c6e-3e0f-4834-aa39-8ca9c3b40ef5
< 2.2.5
MEDIUM 4.3 The Social Slider Feed plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
9316796b-312f-4562-b92f-7de0129e4163 MEDIUM 4.3 The Theme Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
9311c7b6-2c32-4f30-8286-6d59c267c09d MEDIUM 4.3 The Auto Login New User After Registration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
92f26c43-cc7a-4a7a-be11-2eb1cf358a3d MEDIUM 4.3 The Curly - A Stylish WordPress Theme for Hairdressers and Hair Salons theme for WordPress is vulnerable to Insecure Dir… wordfence
92d9b21a-3f53-4f37-b439-56865e39e984
< 2.2.9.1
MEDIUM 4.3 The JetTabs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2… wordfence
92ccd3dd-3fad-47f9-8cc3-99be4bb8906a
< 1.4.8
MEDIUM 4.3 The WP Plugin Manager – Deactivate plugins per page plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
92bdf5c9-37ef-450a-874c-e21a60b03baa
< 1.6.2
MEDIUM 4.3 The ARForms Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
92b4d800-2895-4f7b-8b3b-ee6df75a7908
< 10.41
MEDIUM 4.3 The Subscribe2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.40.… wordfence
92ad097a-9559-42c0-baed-b4d0ada19711 MEDIUM 4.3 The XV Random Quotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
← Prev 1442 1443 1444 1445 1446 1447 1448 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top