πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1447 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
91a83f52-069e-4611-9b46-4a1913e23f42
< 6.0.7.2
MEDIUM 4.3 The RegistrationMagic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
91a2fa6e-f434-4b56-af68-71e1ee565cc8
< 10.17
MEDIUM 4.3 The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable … wordfence
91a20180-871b-4208-b11e-d3ff2a7e8d23
< 3.2.7
MEDIUM 4.3 The CM Answers – Powerful WordPress Forum Plugin plugin for WordPress is vulnerable to unauthorized access due to a mi… wordfence
91a1278a-0308-4fe0-a46e-172ca1735c53 MEDIUM 4.3 The Mavis HTTPS to HTTP Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
919dd168-1b4c-4e3a-977e-051cb48eaded
< 3.0.3
MEDIUM 4.3 The Order Limit for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
917a6b76-0bb4-4320-9ab9-bc433b6dfbe8
< 1.0.2
MEDIUM 4.3 The HomeLancer theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
916c2984-292c-458b-b3be-c187e7c4d30a
< 1.6.2
MEDIUM 4.3 The Document & Data Automation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
915f81ec-8b48-4036-90c6-9a1c31febfdd
< 1.1.35.2
MEDIUM 4.3 The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable… wordfence
91531e13-5344-442c-99d3-8ccfd61b715d
< 2.0.5
MEDIUM 4.3 wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary … wordfence
9148268a-1179-4bc5-b388-309cf08510d7
< 1.6.1
MEDIUM 4.3 The KB Support plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th… wordfence
91427e3e-fedb-407e-8af6-8f4411a4166a
< 13.5.6
MEDIUM 4.3 The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… wordfence
913a94ad-f425-4d24-9e23-7074ecfed8ad
< 2.6.0
MEDIUM 4.3 The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
91272920-fec6-4c75-b7d9-a97a23a54742
< 1.2.1
MEDIUM 4.3 The Print PDF Generator and Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
912488f1-c06c-4504-a3d8-a3730c4253b0
< 1.1.13
MEDIUM 4.3 The Order Cancellation & Returns for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference … wordfence
9122068b-567f-462e-86b8-0419804bd46c
< 4.0.0
MEDIUM 4.3 The AWCA – The Great Analytics Insights for Your eStore plugin for WordPress is vulnerable to unauthorized access due … wordfence
911d083a-57d2-4574-a5b3-b299c368400c
< 5.20.0
MEDIUM 4.3 The Citadela Listing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and excluding, … wordfence
9114018f-0678-4973-bb1e-932f0d93f963
< 1.8.2
MEDIUM 4.3 The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … wordfence
91062d2c-f2a6-4a92-b684-e133391afe60
< 1.2.7
MEDIUM 4.3 The WP Education plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.… wordfence
90e69e43-597c-4c18-b581-d99dacefb9b8 MEDIUM 4.3 The ShortCodes UI plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9… wordfence
90c774a5-e315-4671-a21b-ccfd1b1346ac
< 1.11.8
MEDIUM 4.3 The WS Form LITE plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.11.7. Thi… wordfence
90c71b01-f82e-4f06-b1c9-6a2a5618a744 MEDIUM 4.3 The Login Logger plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
90b7fa47-ca32-41a6-ae9c-e15f361c6398
< 3.9.1
MEDIUM 4.3 The SMS Alert Order Notifications plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
90ab885e-b4df-4774-96e0-53cff569713a
< 1.7.2
MEDIUM 4.3 The Image Optimizer by Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
909d9b9b-78da-41c0-87bc-54730f452bff MEDIUM 4.3 The Epicwin Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
908ef8e1-d4dc-4348-90b8-d8f38666d9ed
< 5.3.10
MEDIUM 4.3 The Modal Window – create popup modal window plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… wordfence
← Prev 1444 1445 1446 1447 1448 1449 1450 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top