πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1463 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
80e2a376-ae15-4883-8a80-0b867fbeeb4c MEDIUM 4.3 The GST for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
80dd4f6a-20dd-4532-913b-ab08f89db836
< 1.0.16
MEDIUM 4.3 The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabilit… wordfence
80b57df9-f5a6-408b-be1b-1cc7fc28ed76
< 3.4.20
MEDIUM 4.3 The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to… wordfence
80b27cde-68d7-439d-aee6-a390035e2022 MEDIUM 4.3 The Forms Rb plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.9. Thi… wordfence
80b15512-210c-4c6b-a3ad-f5d6042091a3
< 2.4.3.1
MEDIUM 4.3 The myCred WordPress plugin before 2.4.3.1 does not have any authorisation in place in its mycred-tools-select-user AJAX… wordfence
80b02df4-9003-44bc-8d6e-695b2cd87bc0
< 3.1.0
MEDIUM 4.3 The Uploadcare File Uploader and Adaptive Delivery (beta) plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
80ad0b55-bd85-4240-ae54-f72d6b81ea7c MEDIUM 4.3 The Multi Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.0.… wordfence
80902e0d-39fd-48c0-96e5-774c91113d1c
< 3.2.0
MEDIUM 4.3 The Advanced Settings 3 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
807764ae-b898-416d-81ca-be2374a6d73f
< 1.20.0
MEDIUM 4.3 The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable … wordfence
806f7e7c-3e0b-40a0-a1a9-05bdf723d3b9 MEDIUM 4.3 The Slide Banners plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
805c46ec-0b8a-4a40-bfc9-5d2d8d43a17b
< 2.0.19.3
MEDIUM 4.3 The WP Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the… wordfence
805b070e-0575-42d8-8e16-b2467afe8ebc
< 1.8.17
MEDIUM 4.3 The BA Book Everything plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
8056d44f-7089-4645-bd73-65e8a5f48502 MEDIUM 4.3 The Quick Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
8035484b-dc2f-4d54-802b-b09bd88a8bf6 MEDIUM 4.3 The Comments Ratings plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
80228d74-498f-4fd5-a378-c9254045b64e
< 1.6.4
MEDIUM 4.3 The Error Monitoring by Bugsnag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
80192348-dcf4-4bab-80d1-ae7a4d194270
< 2.0.9
MEDIUM 4.3 The Breeze plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. Thi… wordfence
7ff038a7-4997-4a14-9846-2b8aea9a2bf3
< 1.2.2
MEDIUM 4.3 The Preschool and Kindergarten theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
7feecce5-f2ce-4278-b648-e363b1fa5d7a
< 3.9.12
MEDIUM 4.3 The Locatoraid Store Locator plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.11… wordfence
7fe4c0ee-8b85-488f-81be-98316d21e160 MEDIUM 4.3 The User Rights Access Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
7fe3849a-05df-4530-91af-be0402169544 MEDIUM 4.3 The Martfury - WooCommerce Marketplace WordPress theme for WordPress is vulnerable to unauthorized access due to a missi… wordfence
7fcd0410-9423-4349-8d1c-3551de38a7c7
< 2.6.2
MEDIUM 4.3 The Custom Field Template plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… wordfence
7fbad834-7e28-4e32-bd88-7751ec2d630b
< 3.0.0
MEDIUM 4.3 The NewsmanApp plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.7.… wordfence
7fa2c000-7cb1-4f77-baa3-dbeeeccb9c01
< 2.0.9
MEDIUM 4.3 The Flashy Marketing Automation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
7f94efa6-b88b-442d-8162-f03efa7f2f65
< 2.1.3
MEDIUM 4.3 The Elespare – Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Codi… wordfence
7f9069b7-a9b2-4b34-8de8-9fd491c19a7b
< 1.30.13
MEDIUM 4.3 The MultiParcels Shipping For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
← Prev 1460 1461 1462 1463 1464 1465 1466 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top