πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1450 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8ec87dd1-9ff3-474d-a913-a31fa9747d0d
< 4.7
MEDIUM 4.3 The Esselink.nu Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
8ea64186-9f25-4685-b435-7890e8d0d1ee MEDIUM 4.3 The modernize theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
8ea53b11-37fa-4c45-a158-5a7709b842fc
< 5.1
MEDIUM 4.3 The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
8ea0e5ae-c8b8-4782-a130-e5460a81b066
< 3.1.0
MEDIUM 4.3 The Hide Admin Bar Based On User Roles plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions befo… wordfence
8e96b53e-218e-416e-8910-940ed2093f0f
< 1.2.9
MEDIUM 4.3 The Tablesome plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
8e94d308-8d36-487e-be72-e1599c4384f9
< 3.0.8
MEDIUM 4.3 The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPr… wordfence
8e93072c-eb0c-46a7-8ed7-7f48916dab50 MEDIUM 4.3 The WordPress Ping Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
8e8e967f-f627-4c0c-ac0f-0a66ae25c602
< 3.6.9
MEDIUM 4.3 The WP User Frontend plugin for WordPress is vulnerable to unauthorized functionality use due to a missing capability ch… wordfence
8e8c2aa5-5770-4b88-b415-40c2aff69d84
< 2.8.0
MEDIUM 4.3 The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a mi… wordfence
8e7cbe45-5dd5-4b8f-8504-a52358156838 MEDIUM 4.3 The ACF Front End Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
8e76fe1d-6315-41ae-bde1-47e0bb2264fc MEDIUM 4.3 The TinyMCE Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… wordfence
8e75bc13-4a9c-439d-a361-33711886bfac
< 1.2.5.4
MEDIUM 4.3 The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missin… wordfence
8e75a03b-7552-4228-a4d0-13c78d20f6d5
< 7.8.6
MEDIUM 4.3 The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post d… wordfence
8e68cb68-45ab-4c2f-a105-1ef01da42453 MEDIUM 4.3 The TopBar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0.… wordfence
8e688654-8e21-48e8-a497-06812f3be9fb MEDIUM 4.3 The Silencesoft RSS Reader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
8e6627f8-9fc4-426a-977a-e3e0f9c857ee MEDIUM 4.3 The StaticPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
8e5d8419-3dff-45f0-b91b-a9c69f5d3e98 MEDIUM 4.3 The Frontend File Manager Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
8e5c3d74-1240-4501-856f-18a1c6369d1c
< 2.0.5.6
MEDIUM 4.3 The Master Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capab… wordfence
8e43e19a-5624-4e17-8f9b-40ce2cf9c150
< 4.5.6
MEDIUM 4.3 The WooCommerce Fortnox Integration plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
8e37331b-0b75-41ee-b390-532efd674cc1
< 4.23.12
MEDIUM 4.3 The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unau… wordfence
8e323b87-7b2e-4e5c-94a4-a4a0712f50ba MEDIUM 4.3 The Mamurjor Employee Info plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
8e1371a5-ed2e-4a1b-901e-8aef4d0d3acf
< 5.33.1
MEDIUM 4.3 The MailPoet – Newsletters, Email Marketing, and Automation plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
8e12950d-9896-4fad-bf6e-239f5ed501e5 MEDIUM 4.3 The Accordion Slider Gallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
8e125188-4aff-4c64-b4ec-a363db2431b7 MEDIUM 4.3 The WP Users Media plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
8e103afe-3ae7-413f-92b2-0e4dd9436f3e MEDIUM 4.3 The Gold Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… wordfence
← Prev 1447 1448 1449 1450 1451 1452 1453 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top