πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1460 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
84554aaa-2b91-4435-a082-25bfa823156e
< 1.2.6
MEDIUM 4.3 The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable… wordfence
844c5012-f823-46ae-8de2-e2803b7cd063
< 1.1.5
MEDIUM 4.3 The Lightweight Sidebar Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
8445aed7-107c-4627-9390-b4b5eb402b11
< 1.6.2
MEDIUM 4.3 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
8445140c-05ce-4d21-9367-97db0f33a47a
< 5.0.2
MEDIUM 4.3 The SiteLock Security – WP Hardening, Login Security & Malware Scans plugin for WordPress is vulnerable to unauthorize… wordfence
8441e5f2-cff0-4f6c-a584-861650f5a121
< 2.9.2
MEDIUM 4.3 The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
843aae1e-f926-42b1-80fc-48910111b1f4 MEDIUM 4.3 The Theme Options Z plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
8438ea46-9ac1-4ef5-a436-e438c35a4321 MEDIUM 4.3 The Baidu Tongji generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
842d12fd-86bc-4dd5-9926-ab4093d4c03e
< 1.2.3
MEDIUM 4.3 The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to unauthorized ac… wordfence
84141197-b6a7-44fa-8058-e9f192d1d56f
< 2.5.2
MEDIUM 4.3 The Droip plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a… wordfence
84003388-c47c-41db-8d2d-4643aa375a89 MEDIUM 4.3 The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability che… wordfence
83bd48fb-f5f9-4d3d-8fc4-a06adfa5a225
< 1.6.1
MEDIUM 4.3 The WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon plugin for WordPress is vulnerable to unauthorize… wordfence
83b91ce9-a060-47db-8120-bbed45889f9f
< 1.8.0
MEDIUM 4.3 The Cooked – Recipe Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
83af4ee4-2763-4706-8cb2-fa102a72be68
< 2.8.2
MEDIUM 4.3 The Linear plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1.… wordfence
83aa1e83-45ff-4aa5-9c06-f79bdc3bf6c0 MEDIUM 4.3 The QuickCal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
83a7e451-6d8f-48aa-9774-46e3d4434330 MEDIUM 4.3 The Subscribe plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
83a2abb6-ecc8-446f-a99b-603d65872d29 MEDIUM 4.3 The News Ticker for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
839c29bd-c064-495c-9c4f-37e12843336f MEDIUM 4.3 The PayPal Marketing Solutions plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
83936cda-e868-44f6-be5d-f26086bc4688
< 3.2.30
MEDIUM 4.3 The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPre… wordfence
837f49e6-dcba-4451-bbbe-14890ab87207 MEDIUM 4.3 The Latest Tabs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
837e596e-a4a7-4fcf-a761-aed35a789770 MEDIUM 4.3 The WP-Reply Notify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
83633ccd-923d-4d74-9429-7c7d93a24323 MEDIUM 4.3 The WPLingo – Forum Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
83624120-bc7b-4778-b6e5-aebe478d3f19
< 1.3.1
MEDIUM 4.3 The Cyrlitera – transliteration of links and file names plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
835941f1-e2f6-41aa-9a46-cdbeb5741d20
< 1.1.51
MEDIUM 4.3 The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_… wordfence
834c6a56-7b02-4f5d-9e10-94ba7da6d47e
< 3.7.42
MEDIUM 4.3 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthor… wordfence
8341eaea-cc54-43e2-bc4f-a892e3756fa3
< 2.5.10
MEDIUM 4.3 The Advanced Cron Manager – debug & control plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
← Prev 1457 1458 1459 1460 1461 1462 1463 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top