πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1458 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
86b0558b-74ed-4ddd-9b18-e7795cefc00e
< 3.6.20
MEDIUM 4.3 The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to Cross-Site Req… wordfence
86a85e07-8359-441f-abb4-a1ca6083e6cd MEDIUM 4.3 The Zawgyi Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
86a69b00-5258-473d-840a-54800d28ea98 MEDIUM 4.3 The Purge Varnish Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
86837f87-ea91-404a-92ac-38d1abf14cde
< 1.1.3
MEDIUM 4.3 The Leadster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. T… wordfence
867d706c-31f9-44ac-ae25-5b722b85a4c8 MEDIUM 4.3 The Similarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.… wordfence
8679f4cd-2cb8-48ad-a531-a00c1b85ed2e
< 5.9.0
MEDIUM 4.3 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object R… wordfence
8671bf69-640d-4656-ae22-a46daadf58a0
< 0.9.8
MEDIUM 4.3 The POEditor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.9.7. T… wordfence
8671b549-2cce-4f38-ad2d-a9472f7e8e7b
< 1.6.4
MEDIUM 4.3 The Serial Numbers for WooCommerce – License Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
8664fec3-4e11-4775-a5ca-b4f58931da76
< 1.5.7
MEDIUM 4.3 The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
865b87a8-ab8a-4054-9e18-50693023cb96 MEDIUM 4.3 The Lafka Plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_opti… wordfence
86502cdf-f726-4f58-a674-fa35f90db943
< 2.0.9
MEDIUM 4.3 The AutoWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. Thi… wordfence
864ca2e5-c421-4aa2-b3c8-1c22ef54ef34 MEDIUM 4.3 The Bulk Me Now! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
863a3087-8009-468a-a33a-3ec4a34681c1 MEDIUM 4.3 The Contact Form 7 reCAPTCHA plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
86351e2c-8c5a-4d71-bd73-d5ae1f03038f
< 6.4.7.2
MEDIUM 4.3 The Events Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.… wordfence
862fa0c3-c16f-493e-9bf6-92debc0e30f6
< 1.3.2
MEDIUM 4.3 The Multiple Roles plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
862f331d-4bb9-4249-a224-3eee4802ee6f MEDIUM 4.3 The WP System Information plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… wordfence
861325b1-92ca-4cd1-aa94-089de1ccba96
< 1.31.1
MEDIUM 4.3 The Equalize Digital Accessibility Checker – Audit Your Website for WCAG, ADA, and Section 508 Accessibility Errors pl… wordfence
860c2339-b2a9-4a4e-a186-07a5fb042b06
< 2.8.2
MEDIUM 4.3 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor… wordfence
86098d46-9e88-4558-b9b2-e3905716f2a9
< 1.0.19
MEDIUM 4.3 The Smart Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
85ff1468-2cbf-4c25-9fc6-9ee419dcaea8 MEDIUM 4.3 The Penci AI SmartContent Creator plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
85e17f3a-cec1-41de-b3e2-ac06a9c9290f
< 1.5.1
MEDIUM 4.3 The KODO Qiniu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 1.5.1 (exclusive).… wordfence
85d2bd06-c2b7-47ad-ae24-fbedf30bbf33
< 0.6.10
MEDIUM 4.3 The Tableberg – Simple Gutenberg Table Block plugin for WordPress is vulnerable to unauthorized access due to a missin… wordfence
85c18159-b08e-441b-8e12-51e046f5f739 MEDIUM 4.3 The mb.YTPlayer for background videos plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
85b6262c-2576-4177-a683-44464dba0978
< 2.0.0
MEDIUM 4.3 The Constant Contact Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
85b61e0f-3bb2-4688-b513-14f4d2da6c30
< 2.4.1
MEDIUM 4.3 The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… wordfence
← Prev 1455 1456 1457 1458 1459 1460 1461 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top