πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1448 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
90867c8b-a025-4c46-986f-9e83866033b5
< 8.0.0
MEDIUM 4.3 The Element Pack Pro - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to unauthori… wordfence
90863334-9464-466b-bb32-870c78095ca4
< 1.0.117
MEDIUM 4.3 The Royal Elementor Kit theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
9075a705-e72f-4331-ab8f-bb06e1a58225 MEDIUM 4.3 The Relocate Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
90752d8a-2e0c-4d46-8a49-778fe06361bd
< 9.0
MEDIUM 4.3 The Emergency Password Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
904e9ac2-1f28-43ba-914c-3b4fd5a0bb22 MEDIUM 4.3 The Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
9049ac31-b79a-4872-a522-2930fb1dfea6
< 4.1.4
MEDIUM 4.3 The WC Marketplace plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versio… wordfence
9046f2cd-f046-46ce-b91c-db9d036ab1fb MEDIUM 4.3 The Navayan Subscribe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
9020faf4-0577-41d9-b005-4d4ffc99ba30 MEDIUM 4.3 The Admin Menu Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
901d4e10-06e9-4acd-ba4a-85a537fa10bc MEDIUM 4.3 The T1 Theme for WordPress is vulnerable to Open Redirect in versions up to, and including, 19.0. This is due to insuffi… wordfence
901cc40d-fa20-4a1f-b01a-e3295891ebda
< 2.3.4
MEDIUM 4.3 The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements plugi… wordfence
901baf71-03b5-4493-9318-ba28dcb97dbe
< 2.6.7
MEDIUM 4.3 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
900e6528-f350-4e1b-80a5-aa01248323a8
< 1.12.0
MEDIUM 4.3 The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modificatio… wordfence
9009deff-bf5a-4434-8f73-1485f733d599
< 1.10.0.3
MEDIUM 4.3 The Contact Form by WPForms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
900339ef-7481-4c55-ab1d-df2617987520
< 2.5.9
MEDIUM 4.3 The CMSMasters Content Composer plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
900294ef-dedb-49d3-b544-eae64399ea03
< 20251128
MEDIUM 4.3 The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… wordfence
8ff9d034-3c6e-4f8f-a53e-86ad85cc10e6 MEDIUM 4.3 The Restore Permanently delete Post or Page Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
8ff3b35c-f7e3-4cae-b7f1-1a0930173ac5
< 26.6.3
MEDIUM 4.3 The Betheme theme for WordPress is vulnerable to authorization bypass in versions up to, and including, 26.6.2. This is … wordfence
8ff2a842-2e46-4267-bbf1-e7d9d4a7e277
< 3.2.9
MEDIUM 4.3 The Sunshine Photo Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on t… wordfence
8ff16906-2516-4b3c-8217-e3fb24924e27
< 3.1.14
MEDIUM 4.3 The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to … wordfence
8ff05617-61b1-4d1f-9230-c771f23d3283 MEDIUM 4.3 The Custom Post Type Page Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
8fe7dc0e-3b8c-409d-a66a-2f67b88d0d32
< 3.0.5
MEDIUM 4.3 The Graphina plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several func… wordfence
8fe7b884-c245-4412-b43d-38d0565fccbd
< 3.6.5
MEDIUM 4.3 The Textmetrics plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
8fe0cb36-7b61-412f-ad2a-d31b18417ce8
< 2.0.74
MEDIUM 4.3 The Radio Player plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
8fd845f2-9943-462a-afab-bd19b8064a88 MEDIUM 4.3 The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
8fc88821-b2be-49a5-a2cf-53e87d0349a2 MEDIUM 4.3 The WP Shamsi plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the '… wordfence
← Prev 1445 1446 1447 1448 1449 1450 1451 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top