πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,423
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,423 vulnerabilities found (page 1465 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7f4cf85d-6105-4f7d-b4a0-18a3513a93a8
< 1.2.7
MEDIUM 4.3 The Conditional Menus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
7f4959a8-21e7-4cbf-a150-704abc956f31
< 3.14.0
MEDIUM 4.3 The Seriously Simple Podcasting plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
7f341562-232e-437f-8d3d-83a06402e8ef
< 1.8.8
MEDIUM 4.3 The Envira Photo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
7f15ac06-b5d3-4265-b69b-1d46b12a0522
< 1.6.6
MEDIUM 4.3 The Spreadshop Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
7f0eac1e-4988-4b73-bf13-c959b0dc11e2
< 1.15.17
MEDIUM 4.3 The Form Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th… wordfence
7ee6ca74-3684-46df-9b42-e97ee8cdbdb8
< 3.0
MEDIUM 4.3 The WiserReview Product Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
7ee68705-cbb3-44b8-8223-4cecd678bcab
< 2.5.7
MEDIUM 4.3 The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missin… wordfence
7ec14923-0f68-45e8-8d99-9921c5928ac4
< 5.9.5
MEDIUM 4.3 The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthoriz… wordfence
7ec03e35-9de7-44e8-88be-5a374edd8984
< 1.1.4
MEDIUM 4.3 The Financio theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.3… wordfence
7eb53a80-89e5-4d8c-a1ba-c272196a3340
< 2.20
MEDIUM 4.3 The ARK Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.19. This is due to m… wordfence
7ea78c3f-f033-4a47-8190-07ae2552fdd2
< 4.7
MEDIUM 4.3 The SearchIQ plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.6. Thi… wordfence
7e805a72-b49e-4f0a-83c6-be55d14812d2 MEDIUM 4.3 The Robots.txt rewrite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
7e7d3bf0-1860-45b0-b928-2291b0f98902
< 3.3.3
MEDIUM 4.3 The Top 10 – WordPress Popular posts by WebberZone plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
7e7044aa-a1e7-4b1d-9f50-5e250426c6b0
< 1.6.3.1
MEDIUM 4.3 The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a m… wordfence
7e6f9f8c-a36b-412d-a2ae-cc90e3a840f6 MEDIUM 4.3 The Kimili Flash Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
7e5b1e90-53f7-4afc-9544-c36afe1ee813
< 5.7.3
MEDIUM 4.3 The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to un… wordfence
7e539549-1125-4b0e-aa3c-c8844041c23a
< 2.2.2
MEDIUM 4.3 The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
7e452aa0-bfb9-4805-b2ed-53464a4b5308
< 4.8.6
MEDIUM 4.3 The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sy… wordfence
7e3f3104-e213-4b0f-9821-b3f1a5c06191
< 6.5
MEDIUM 4.3 The WP EXtra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4. Thi… wordfence
7e3ae5e7-1f41-48cd-8aea-698e3b00066c
< 4.8.7
MEDIUM 4.3 The Total Poll Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… wordfence
7e31400c-e22d-406b-a8d6-244f68f9f27d
< 1.27.9
MEDIUM 4.3 The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Cross-Site R… wordfence
7e23b7a5-8ee6-4818-a52e-4fa66bee02e2 MEDIUM 4.3 The Avatar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, … wordfence
7e232114-c14a-43a7-bc78-423f7e5b35fb
< 2.3.7
MEDIUM 4.3 The OnePress theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.6. Th… wordfence
7e210be9-3acb-4b42-8882-0f5f57eac964 MEDIUM 4.3 The Easy 301 Redirects plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
7e0e00ec-f7c2-4c1b-802a-acf0892d2083
< 3.3.12b
MEDIUM 4.3 The Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
← Prev 1462 1463 1464 1465 1466 1467 1468 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top