πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1446 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
92a35989-2b71-4eca-aae0-c8ea0d60ce40
< 2.7.9
MEDIUM 4.3 The Five Star Restaurant Reservations plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
9296deb9-51c5-4390-b121-2f6ac8adcc97
< 1.8.1
MEDIUM 4.3 The ITERAS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.0.… wordfence
92967831-fb76-494e-af95-146dc26b01d9
< 1.6.1
MEDIUM 4.3 The Solace Extra plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
92947896-5ec1-4c5c-9eed-37f3566dbf6f MEDIUM 4.3 The UDesign Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
928dd5c1-c396-4ddb-b910-697884dbc824
< 4.16.4
MEDIUM 4.3 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery… wordfence
9288ed60-b14b-4188-84d4-efe770093551
< 4.1.1
MEDIUM 4.3 The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vu… wordfence
928352ea-f6ce-4bc7-8f0c-8e3c4d075a95
< 5.9.9.7
MEDIUM 4.3 The ProfileGrid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
926e5e4c-ea78-46f2-8fac-d9ee71aeaab8
< 3.0.2
MEDIUM 4.3 The Advanced Settings 3 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
926c09d5-3824-4745-99f6-50d9c945d252
< 5.9.5
MEDIUM 4.3 The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing capability check… wordfence
9269c3e7-2495-4665-ad08-d6dcf659db21
< 2.3.6
MEDIUM 4.3 The WordPress Comments Import & Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
926550bb-265d-4811-a375-10c47e9fb4d6
< 1.4.4
MEDIUM 4.3 The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to unauthorized modification … wordfence
92651031-e6f4-46af-bd5d-d37a2834b56b MEDIUM 4.3 The SoftMe theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in a… wordfence
924b98eb-c352-44ea-a0b7-42abc3df730b
< 1.3.62
MEDIUM 4.3 The Falang multilanguage for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
924a06a0-361e-4ecc-9db2-0375db7cf87a
< 9.22
MEDIUM 4.3 The WP Spell Check plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.… wordfence
92424e24-17db-45dc-804b-32a411f0b233
< 1.4.3
MEDIUM 4.3 The Easy!Appointments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
923a274e-b41b-43a1-9069-4ffcb40a0a12
< 1.12
MEDIUM 4.3 The Layouts for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
9231645c-aadd-4bc9-a5b7-b94802a2dd1e MEDIUM 4.3 The User Sync ActiveCampaign plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
922f981d-3c14-48d3-881e-9d3a08bfab57
< 2.0.9
MEDIUM 4.3 The Big Store theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
922ced40-defd-42a5-a57e-09e8397c7409 MEDIUM 4.3 The Spare - Ultimate MultiPurpose LESS Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
9225ebc6-bff9-4176-a86e-022ff8ec3b05
< 7.7.10
MEDIUM 4.3 The LayerSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.7.9… wordfence
91ea157f-7a74-427f-b1eb-a9187f2d9096 MEDIUM 4.3 The tencentcloud-cos plugin for WordPress is vulnerable to unauthorized access to several functions associated with AJAX… wordfence
91dbc521-c24b-4b73-9b70-46d363ccb535
< 21.0.10
MEDIUM 4.3 The Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to u… wordfence
91cd949f-5e6f-41cb-9a93-f3d763a8cece MEDIUM 4.3 The Export All Post Meta plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
91ba93de-4c5f-4611-8296-adfc85c8dd2b
< 5.1.1
MEDIUM 4.3 The EasyAzon – Amazon Associates Affiliate plugin for WordPress is vulnerable to unauthorized use of AJAX actions due … wordfence
91a9e602-44c6-4148-8316-27760f9e5c61 MEDIUM 4.3 The Display product variations dropdown on shop page plugin for WordPress is vulnerable to unauthorized access due to a … wordfence
← Prev 1443 1444 1445 1446 1447 1448 1449 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top