πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1453 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8bed0637-6d1b-4c30-b87c-01c88d573ae6
< 3.7.18
MEDIUM 4.3 WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path… wordfence
8be739cd-e594-41a5-85a4-9cf7d3436953
< 3.7.22
MEDIUM 4.3 Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive… wordfence
8bdf6a52-7316-440b-9d36-d405a672dce1
< 4.3.19
MEDIUM 4.3 The BWD Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… wordfence
8bd4a111-9d60-4ff7-83bc-24e9aaeff907 MEDIUM 4.3 The Cocco - Kids Store and Baby Shop WordPress Theme theme for WordPress is vulnerable to Insecure Direct Object Referen… wordfence
8bced7df-3e1a-4d7b-9ad0-64be5e18900f
< 3.4.8
MEDIUM 4.3 The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable … wordfence
8bcdaf14-aa5d-4c23-8250-8d0d22ac6191
< 2.2.6
MEDIUM 4.3 The Travel Booking theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in al… wordfence
8bca36f7-4087-4378-b4f6-6c0bb24f24ff MEDIUM 4.3 The WordPress Buffer – HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule plugin for WordPress… wordfence
8bb9b6e3-0c86-44aa-9e26-9de656822f59
< 25.05.13
MEDIUM 4.3 The Team Showcase plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
8bb71f5d-a766-4f39-a2c6-78644cdd2882
< 1.52.2
MEDIUM 4.3 The Broadstreet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
8bb5abff-d762-459a-b96c-5cbbb9f5a22e MEDIUM 4.3 The Social Media Icons Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
8bb330be-f12c-475c-97b6-745a1e6edb58
< 1.2.3
MEDIUM 4.3 The Integration for Contact Form 7 and Zoho CRM, Bigin plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
8babc42a-c45c-423f-bd09-da7afb947691
< 1.1.2
MEDIUM 4.3 The Posts Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… wordfence
8b9ba35b-5ef8-4170-97f4-400fe9bd3af2
< 1.7.11
MEDIUM 4.3 The Run Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1… wordfence
8b88b195-6c02-4a11-91de-d21c808650fb
< 1.2.4
MEDIUM 4.3 The Book Landing Page theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
8b8372e0-ab18-4817-b293-b75f4855620d MEDIUM 4.3 The wpNamedUsers plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.5.… wordfence
8b7dd3c0-a91f-4fb4-a47e-38f6d389bf65
< 2.0.0
MEDIUM 4.3 The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to unauthorized access due to a… wordfence
8b771d76-b79a-4ff2-9433-8d35734a4396
< 1.0.7.2
MEDIUM 4.3 The WOLF plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.7.1. Thi… wordfence
8b73f864-68b5-4ba8-93a3-37f2564cc240
< 10.0
MEDIUM 4.3 The Salon booking system plugin for WordPress is vulnerable to unauthorized access and modification of data due to a mis… wordfence
8b56fd35-377a-4d18-abf7-7946e5d4e21c
< 1.3.9
MEDIUM 4.3 The AyeCode Connect plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the i… wordfence
8b421330-dd3c-4af0-9f42-95430117eb9b
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
8b14c07b-23bb-4a14-8018-fa2462383b35
< 1.4.6
MEDIUM 4.3 The HT Event plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.5. T… wordfence
8b0504f3-f8df-4b37-bafa-5320920e9571
< 2.5.5
MEDIUM 4.3 The WooCommerce Shipping Per Product plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… wordfence
8b040f47-b126-4640-9fc5-bda8650f6c69
< 7.32
MEDIUM 4.3 The WP Custom Admin Interface plugin for WordPress is vulnerable to unauthorized admin notice dismissal due to a missing… wordfence
8aef0e9d-fc63-445d-a5fa-08e6cd5f0dbc
< 5.3.7
MEDIUM 4.3 The WooCommerce Multilingual & Multicurrency plugin for WordPress is vulnerable to unauthorized modification of data due… wordfence
8ade80e4-a05a-4418-9c01-67c0366213b6
< 1.8.2
MEDIUM 4.3 The PageLayer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the p… wordfence
← Prev 1450 1451 1452 1453 1454 1455 1456 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top