πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1452 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8d0d5ab9-b56d-4d23-9db6-44b7b8fc361a MEDIUM 4.3 The Walker for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
8cffcb34-4d35-4e1e-bc0a-53a41bc91e87
< 3.12.28
MEDIUM 4.3 The Easy Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and excl… wordfence
8cf507de-d003-43f3-9763-f1cff5508685
< 18.5
MEDIUM 4.3 The Google Review Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
8cd7dfb3-bc73-4f6a-9827-0003452ebf59 MEDIUM 4.3 Cross-Site Request Forgery (CSRF) vulnerability in Private Messages For WordPress plugin <= 2.1.10 at WordPress allows a… wordfence
8ccb9b0c-873d-4d5d-be77-98e4ab27346b
< 49.5.3
MEDIUM 4.3 The WPAMS - Apartment Management System for wordpress plugin for WordPress is vulnerable to unauthorized access due to a… wordfence
8cc25fe1-82f0-493b-a9d3-1a4892e35613 MEDIUM 4.3 The PayPal Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
8cbc45be-72a9-4abb-9997-249f88e48a9a MEDIUM 4.3 The Simple Contact Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
8ca1bf69-bc71-4137-a908-58c1915f654a
< 0.9.69
MEDIUM 4.3 The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver… wordfence
8c9c37e2-c9f7-4a07-94d0-51298d98ff80
< 11.2.4
MEDIUM 4.3 The Quiz And Survey Master plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and… wordfence
8c9a223c-6c34-4c64-92b5-d986f9791ebb MEDIUM 4.3 The Purchase Button For Affiliate Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
8c82d209-3c69-4d6e-a129-d519f6601540 MEDIUM 4.3 The login_register plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in al… wordfence
8c7fee7f-b75f-4926-9f0b-cf138be2225b MEDIUM 4.3 The Ray Enterprise Translation plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
8c7d5fbe-d272-46d4-9b33-889ba77dcc52
< 2.5.1
MEDIUM 4.3 The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due… wordfence
8c732b0e-9898-48f2-99b2-068f31532b17
< 1.1.77
MEDIUM 4.3 The WP Time Slots Booking Form plugin for WordPress is vulnerable to unauthorized access of functionality due to a missi… wordfence
8c646335-ef11-42bd-926b-d44372ad3c6f MEDIUM 4.3 The Ultimate twitter profile widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
8c63b5e2-f543-4c12-97c0-c6b11f56ccc1
< 2.17.5
MEDIUM 4.3 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
8c62b50a-f760-40c5-a408-27a6cfd44126
< 1.2
MEDIUM 4.3 The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view othe… wordfence
8c52c496-2f77-4faa-9a73-dafe4a66905d
< 3.6.34
MEDIUM 4.3 The My auctions allegro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
8c4b8521-c6cf-4bdc-a7c9-7ba01d59715c MEDIUM 4.3 The Restrict Elementor Widgets, Columns and Sections plugin for WordPress is vulnerable to unauthorized access due to a … wordfence
8c43870a-6ae7-4c31-b7d0-1cb1afc6be35 MEDIUM 4.3 The Plugin Optimizer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
8c384d30-be18-4dfa-a385-5a8bee38bd14
< 1.2.3.20
MEDIUM 4.3 The Gmail SMTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3.… wordfence
8c076c46-c87c-4fb2-8e8e-b342c016e09a
< 3.5.0
MEDIUM 4.3 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Insecure Direct Object Re… wordfence
8c06d7aa-ac51-4e59-9d5b-ba0961a5e637
< 1.4.1
MEDIUM 4.3 The Rich Table of Contents plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
8c057b43-a544-4448-8370-697ad12b5e4b
< 4.3.3
MEDIUM 4.3 The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
8bf60b2c-773c-44d2-a8d8-47c30be7edc1 MEDIUM 4.3 The Photo Gallery ( Responsive ) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
← Prev 1449 1450 1451 1452 1453 1454 1455 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top