πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1449 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8fc4b815-dc05-4270-bf7a-3b01622739d7
< 3.3.2
MEDIUM 4.3 The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_last_name' … wordfence
8fbc9c82-4736-47d9-88ac-bea0b66d6c9e
< 2.2.1
MEDIUM 4.3 The Crowdfunding plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
8fb7241f-f7fc-48c0-8111-5ceceb156f9f
< 1.11.0
MEDIUM 4.3 The User Feedback plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
8fa382bf-a501-44eb-8a39-7ceb5829378f
< 1.1.9
MEDIUM 4.3 The Marker.io plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.8.… wordfence
8fa1048e-bdcd-41d1-a7c4-196731a60843
< 1.3.4
MEDIUM 4.3 The CF7 Invisible reCAPTCHA plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
8f9ce7a1-3e90-4b98-9fc2-4fcd37d332ed
< 2.35.1.3.0
MEDIUM 4.3 The WordPress Ping Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
8f9cd0f2-1ca6-47cb-94bd-5c286cf9c67f
< 1.2
MEDIUM 4.3 Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remot… wordfence
8f8d7397-0201-4194-8604-057f905ef10b
< 3.5.09
MEDIUM 4.3 The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz… wordfence
8f88ff96-5bd7-448d-a030-e75fd268bff6 MEDIUM 4.3 The LadiApp plugin for WordPress is vulnerable to unauthorized access of data, modification of data, or loss of data due… wordfence
8f847a61-4378-4b04-8eb4-99ef36417b6c
< 4.12.5
MEDIUM 4.3 The GDPR Cookie Compliance plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
8f81ca6c-2479-4193-9f2c-6645cd7bca8a MEDIUM 4.3 The IgnitionDeck plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
8f812539-ebb3-4b80-a599-2e695154d6c0
< 1.3.60.1
MEDIUM 4.3 The Findgo theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.55. Thi… wordfence
8f6fd0bb-d37b-40b6-b84e-9b21aae891cc
< 1.8.2
MEDIUM 4.3 The Easy PayPal Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
8f687ee4-9760-48dd-9427-853de877dacc
< 2.3.71
MEDIUM 4.3 The GeoDirectory plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… wordfence
8f4f7cb9-22ef-46fb-bb0a-98fe9af32d38 MEDIUM 4.3 The Download Media plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o… wordfence
8f4c086d-8209-4212-9d91-67238c1a9143
< 3.3
MEDIUM 4.3 The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.… wordfence
8f342fb7-8f52-43d9-a887-1cf1fffa6ec6 MEDIUM 4.3 The WP Clean Up plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3… wordfence
8f29da38-177e-4c8d-964f-473b2a3e1b78
< 1.2.3
MEDIUM 4.3 The Vilva theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.2. This … wordfence
8f052dfc-609d-43ed-a8bb-e30294749d03
< 3.10
MEDIUM 4.3 The WordPress Email Marketing Plugin – WP Email Capture plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
8ef33e3c-187a-45d9-9dac-0895dce34216
< 5.9
MEDIUM 4.3 The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
8ef2e0b1-52ef-4f70-9e95-d010a586d060
< 1.1.8
MEDIUM 4.3 The Virusdie - One-click website security plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… wordfence
8ee2e088-8206-4a97-98f0-167fef451925
< 2.3.9
MEDIUM 4.3 The JW Player for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
8edaf5ce-6a26-44cc-b4d8-e3b0ccfa9c11
< 6.4.5
MEDIUM 4.3 The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
8ed63de5-ef65-4e90-afc1-b7a075e99316
< 21.3.5
MEDIUM 4.3 The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordP… wordfence
8ecd781f-1bef-4f22-ac1f-88709ea45616 MEDIUM 4.3 The Ntz Antispam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 2… wordfence
← Prev 1446 1447 1448 1449 1450 1451 1452 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top