πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,433
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,433 vulnerabilities found (page 1466 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7e5b1e90-53f7-4afc-9544-c36afe1ee813
< 5.7.3
MEDIUM 4.3 The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to un… wordfence
7e539549-1125-4b0e-aa3c-c8844041c23a
< 2.2.2
MEDIUM 4.3 The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
7e452aa0-bfb9-4805-b2ed-53464a4b5308
< 4.8.6
MEDIUM 4.3 The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sy… wordfence
7e3f3104-e213-4b0f-9821-b3f1a5c06191
< 6.5
MEDIUM 4.3 The WP EXtra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4. Thi… wordfence
7e3ae5e7-1f41-48cd-8aea-698e3b00066c
< 4.8.7
MEDIUM 4.3 The Total Poll Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… wordfence
7e31400c-e22d-406b-a8d6-244f68f9f27d
< 1.27.9
MEDIUM 4.3 The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Cross-Site R… wordfence
7e23b7a5-8ee6-4818-a52e-4fa66bee02e2 MEDIUM 4.3 The Avatar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, … wordfence
7e232114-c14a-43a7-bc78-423f7e5b35fb
< 2.3.7
MEDIUM 4.3 The OnePress theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.6. Th… wordfence
7e210be9-3acb-4b42-8882-0f5f57eac964 MEDIUM 4.3 The Easy 301 Redirects plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
7e0e00ec-f7c2-4c1b-802a-acf0892d2083
< 3.3.12b
MEDIUM 4.3 The Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
7e0ccf7e-1276-4aa8-872f-440528699ba9
< 4.5.2
MEDIUM 4.3 The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorize… wordfence
7e0c9369-55ba-4c1c-a222-d114d146b031 MEDIUM 4.3 The Netease Music plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
7e069678-0c0a-4e4a-b0ee-404f488f9d01
< 3.2.2
MEDIUM 4.3 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
7de4282f-157b-4ba0-b400-e4e9982beb31
< 7.2.8
MEDIUM 4.3 The The Post Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.2… wordfence
7de2cb7a-dc3d-41f2-8faa-9e87f78531b5
< 3.7.8
MEDIUM 4.3 The Kadence Blocks β€” Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization byp… wordfence
7de132d5-51c9-464c-b687-8e367dd8d846
< 1.4.4
MEDIUM 4.3 The WordPress Backup & Migration plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… wordfence
7ddbf1e0-55a9-45d6-953b-0a2e413dbb9d
< 5.0.11
MEDIUM 4.3 The MultiVendorX plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… wordfence
7ddabda2-1e27-4b87-b643-b0166112a890
< 1.9.3
MEDIUM 4.3 The Better Notifications for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
7dd67111-514f-4f7d-8cdd-7b10ea718530 MEDIUM 4.3 The Theme Tweaker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2… wordfence
7dd18e4e-9aa6-403e-aec3-21f33d739066 MEDIUM 4.3 The NGINX Cache Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
7dcde10d-4eb7-42fe-926e-05e56affc521
< 5.2.3.0
MEDIUM 4.3 The RegistrationMagic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
7dc6f6e2-6777-4056-95d0-e3d3e7ad7a22 MEDIUM 4.3 The Norby AI plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… wordfence
7dc65c3e-b55f-416a-8315-36a3d9483154
< 2.8.0
MEDIUM 4.3 The The Grid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
7dc46bc4-ecfb-438f-b951-7b957489cd96
< 8.8.3
MEDIUM 4.3 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized data loss in all … wordfence
7dc41eb7-5c9a-4a67-902d-9a855840668b
< 4.4.5
MEDIUM 4.3 The Essential Real Estate plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation… wordfence
← Prev 1463 1464 1465 1466 1467 1468 1469 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top