πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1455 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
89d3a9da-2496-4f75-ad8f-65629f198fe5
< 4.10.12
MEDIUM 4.3 The Event Espresso 4 Decaf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
89cbe41d-3765-4061-8ef6-b63556a5677c MEDIUM 4.3 The Site Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.… wordfence
89ca9214-145e-43c6-a642-7c371f635332 MEDIUM 4.3 The JTRT Responsive Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
89a05036-93f6-421f-ac64-a26622427ebb
< 15.0.9
MEDIUM 4.3 The Simple Link Directory Pro - AI Powered plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
897ee0c1-9f28-47b5-9b10-f6fd8c4c4f18
< 4.2.4
MEDIUM 4.3 The PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget plugin for WordPress is vulnerable to Se… wordfence
896d69ff-ec05-4811-a959-84f632b4b915
< 1.4.14
MEDIUM 4.3 The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to Cross-Site Reque… wordfence
89696d1c-8e6e-402a-9d7a-03fe0f364a72
< 3.3.2
MEDIUM 4.3 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification … wordfence
89635463-966d-4f7d-995d-ad83a502d95b
< 1.6
MEDIUM 4.3 The Remove Schema plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5… wordfence
894c875a-078f-4c1f-83d2-4a6e4a309c3e
< 3.0.9
MEDIUM 4.3 The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This… wordfence
894ad797-5143-4493-a3d6-29b22cee1cc6
< 11.0.0
MEDIUM 4.3 The AcyMailing SMTP Newsletter plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
8945bae7-2224-4d9f-b693-10c94c94dea0
< 1.17.6
MEDIUM 4.3 The NitroPack plugin for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability … wordfence
8939cad2-f9fc-45aa-97d1-9a1a2a59bf94
< 6.3.8
MEDIUM 4.3 The Simple File List plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
8931a3ab-886c-4618-b413-c25884ef24bc
< 1.8.0
MEDIUM 4.3 The Behance Portfolio Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
89315bf7-19f2-4fec-b9f5-62aa2a928d7a
< 2.8.1
MEDIUM 4.3 The Brizy Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
8925157c-8642-4cbc-89e3-fb2ac148eee6
< 2.1.1
MEDIUM 4.3 The Himer theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. T… wordfence
892372c9-380c-43b2-b928-b5964574c414
< 2.1.0
MEDIUM 4.3 The Wp Ultimate Review plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
891a625e-8248-4d21-a796-bf0cff6fc253 MEDIUM 4.3 The ENL Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
8919ba4e-e217-4e1d-8bd6-4c2387f9680f
< 1.1.6
MEDIUM 4.3 The WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable t… wordfence
89100b33-0e27-4a04-9407-8505524e7e45
< 3.3.0
MEDIUM 4.3 The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to unauthorized a… wordfence
890bcce2-18c2-4df8-a945-0c23437534fc
< 1.0.99
MEDIUM 4.3 The ColibriWP Theme framework used by multiple themes for WordPress is vulnerable to unauthorized modification of data d… wordfence
88fb7e43-26b1-44e4-864a-e6bd6f2c48fa
< 4.8.3
MEDIUM 4.3 The Featured Image from URL plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficie… wordfence
88fa4a43-7126-42e6-9469-25ffbfd8ed17
< 3.2.1
MEDIUM 4.3 The Powerlift - Fitness and Gym WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missin… wordfence
88f6a24f-f14a-4d0a-be5a-f8c84910b4fc
< 2.10.230
MEDIUM 4.3 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
88f51ef6-2207-4e91-9182-48c6babe178b
< 3.3.2
MEDIUM 4.3 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized … wordfence
88dc4a77-0d81-4d90-9a43-cc4d3055e39c
< 8.0.8
MEDIUM 4.3 The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
← Prev 1452 1453 1454 1455 1456 1457 1458 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top