ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1459 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
85a37373-a97f-44b7-a743-bbaaa0056a6c
< 3.3.4
MEDIUM 4.3 The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable to unauthorized a… wordfence
85a33508-71f2-4aa1-8d51-667eb0690fbd
< 5.5.9
MEDIUM 4.3 The WP Data Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.… wordfence
8591cbd0-0bdb-4222-8485-0e96cf15e39f
< 4.7.1.1
MEDIUM 4.3 The Advanced Coupons for WooCommerce Coupons plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
8567a7d7-4f4b-41de-a4e2-03f22f429774
< 2.1.5
MEDIUM 4.3 The Notibar plugin for WordPress is vulnerable to unauthorized plugin activation due to a missing capability check on th… wordfence
85555a8f-5d23-458d-9166-d30f8f0551e0
< 1.2.29
MEDIUM 4.3 The Calculated Fields Form plugin for WordPress is vulnerable to Open Redirect via the plugin's shortcode(s) in all vers… wordfence
85550779-fd46-4130-92f1-b291d4e86b21
< 5.0.1
MEDIUM 4.3 The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Director… wordfence
85546e18-2c66-4199-9909-842e86833927
< 5.4.4.2
MEDIUM 4.3 The Calculated Fields Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
85317781-7e77-4a78-af67-0a1dce39364c
< 2.0.0
MEDIUM 4.3 The Make Paths Relative plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
850a39f9-749d-4429-ab27-90ce2c0b1316
< 4.0.1
MEDIUM 4.3 The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 4.0.1. … wordfence
85069d6a-deaa-43a3-add8-e10293701bec MEDIUM 4.3 The Advanced Appointment Booking & Scheduling plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… wordfence
84f57623-b6a6-4717-857d-93fa9d279882
< 3.3.77
MEDIUM 4.3 The LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Sensitive Information … wordfence
84ec28d1-8634-41df-ab1e-b56ed84f2809
< 3.2.5
MEDIUM 4.3 The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.4. … wordfence
84e9c24c-5507-446d-9bfd-f01244f43449 MEDIUM 4.3 The Woo Tuner plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
84e18c54-4bc2-45c1-90fb-960a862170b6
< 2.9.4.4
MEDIUM 4.3 The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program. plugin for WordPre… wordfence
84db3251-5a01-48dc-b00e-d58c717a4b9e
< 5.5.5
MEDIUM 4.3 The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to Cross-Site … wordfence
84d43356-274e-42d5-ac40-10a34effce8d
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
849f14df-d122-4644-a1af-90a60e1fb003
< 4.14
MEDIUM 4.3 The Newsletters plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
8493d59e-72d0-4d86-91b1-7284c31c1b1d MEDIUM 4.3 The Minimalistic Event Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
84875591-2754-4415-9a77-8824fdfa89dd
< 3.8.1.2
MEDIUM 4.3 The JetEngine plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
846bd929-45cd-4e91-b232-ae16dd2b12a0
< 4.9.1
MEDIUM 4.3 The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 … wordfence
8464a63f-db39-4a2c-b408-d7fd7539d6dc
< 2.5.8
MEDIUM 4.3 The Radio Station by netmix® – Manage and play your Show Schedule in WordPress! plugin for WordPress is vulnerable to… wordfence
845e476a-cc0a-4ee1-853d-bb5b7b081e04
< 3.0.7
MEDIUM 4.3 The Extra Product Options for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to… wordfence
845caaa9-185f-4f06-bae0-d10e2c6ab373
< 1.0.33
MEDIUM 4.3 The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
845c4c37-ed90-40a1-9400-951214534060
< 3.8.0
MEDIUM 4.3 The WP Document Revisions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
845b6bcf-004b-4b92-88d7-3d331fa58c11
< 1.9.7
MEDIUM 4.3 The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
← Prev 1456 1457 1458 1459 1460 1461 1462 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top