πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1457 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
87d684ba-4856-429f-9e4e-baa61c3967e1
< 3.0.4
MEDIUM 4.3 The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object … wordfence
879f298d-a84a-44ea-a3dc-2c5663d52a2a
< 3.51.0
MEDIUM 4.3 The TaxoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3… wordfence
8790bcca-a8c8-4b66-9ecc-47b7783cb224
< 3.7.1
MEDIUM 4.3 The Instapage Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
878653e9-da8e-451b-8f23-7ea3418d3b37
< 2.4
MEDIUM 4.3 The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
878246f7-17c5-4ea0-a450-27244ace2717
< 5.11
MEDIUM 4.3 Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au… wordfence
8777f440-732b-4fef-9830-aa6b92265ddc
< 1.1.6
MEDIUM 4.3 The Tasty Recipes Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
8775662f-d007-4edf-826e-f755d7b11c25 MEDIUM 4.3 The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… wordfence
876d81fd-f8fc-481c-b5d6-e071591ac438 MEDIUM 4.3 The ShrinkTheWeb (STW) Website Previews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
8766608e-df72-4b9d-a301-a50c64fadc9a
< 4.6.1
MEDIUM 4.3 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification … wordfence
8758cda7-06a7-4bc4-b393-bca654f7ecd3
< 6.3.14
MEDIUM 4.3 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… wordfence
874e9e14-1330-40f0-8199-8abcaae58e98 MEDIUM 4.3 The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to Cross-Sit… wordfence
873deede-6fcc-48b8-8b26-2661b83107d9
< 3.11.7
MEDIUM 4.3 The WPS Bookings for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions … wordfence
873b54ba-d29f-4e09-9dc1-a38c10ebfcb1
< 1.0.58
MEDIUM 4.3 The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … wordfence
872f13bc-e6d0-4307-b2c9-b55a44df1016
< 2.2.17
MEDIUM 4.3 The WordPress Live Chat Plugin for WooCommerce – LiveChat plugin for WordPress is vulnerable to Cross-Site Request For… wordfence
872c61aa-c95c-4b86-8e39-8112bb117a0b
< 3.1
MEDIUM 4.3 The Meta-box GalleryMeta plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
8726375f-de67-4c92-9cf8-1bfb7330f327
< 3.28
MEDIUM 4.3 The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads dir… wordfence
871b94a8-d2ab-4135-8087-80a51f7fea11
< 1.7.06
MEDIUM 4.3 The Workscout Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 1.7.06 (exclus… wordfence
86fe195e-7ebf-4840-89e2-619a238c3082
< 1.32.00
MEDIUM 4.3 The e2pdf plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
86f84434-ac85-4c5f-8dd7-11d02ae9ee89
< 6.4.1
MEDIUM 4.3 The Photo Engine (Media Organizer & Lightroom) plugin for WordPress is vulnerable to unauthorized access due to a missin… wordfence
86e3eae3-21bb-4695-8650-4c6ba6ababe3
< 1.3.5.2
MEDIUM 4.3 The HUSKY – Products Filter for WooCommerce (formerly WOOF) plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
86ca6f9f-5a04-4e56-a7c7-d18a0c6fdad4
< 2.7.7
MEDIUM 4.3 The Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Part… wordfence
86c8f14a-bb64-41bb-9ab7-dd86f122dc4c
< 11.1.5
MEDIUM 4.3 The Quiz And Survey Master plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
86c7bca9-4290-4c71-9a1a-7f14032075d5
< 2.1.19
MEDIUM 4.3 The Arconix Shortcodes plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
86bd6ae1-e74d-4aab-98e1-3c47cb484fe9
< 1.1.19
MEDIUM 4.3 The Inline Image Upload for BBPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
86b8844e-5d6f-4bc6-97b2-4ff487bb2188
< 1.2.5
MEDIUM 4.3 The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lsw… wordfence
← Prev 1454 1455 1456 1457 1458 1459 1460 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top