πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1467 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7dc41eb7-5c9a-4a67-902d-9a855840668b
< 4.4.5
MEDIUM 4.3 The Essential Real Estate plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation… wordfence
7dc34ff1-1b7e-4974-907a-745911df5dc8
< 4.17.0
MEDIUM 4.3 The FG Drupal to WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
7db39101-f16d-4a4b-8165-437af63d55e7 MEDIUM 4.3 The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
7db0a94e-2633-4f62-adb6-9acb3f884cb8
< 28.1.2
MEDIUM 4.3 The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to una… wordfence
7d9d7cab-c840-469f-ba2d-f81c785ffb8f
< 4.2
MEDIUM 4.3 The GEO my WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
7d7abd28-43be-49a7-9b2e-2e44e9208db1
< 1.2.6
MEDIUM 4.3 The Rara Business theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.… wordfence
7d6c19e2-b280-4937-8f66-eac1da3cd365
< 3.2.6
MEDIUM 4.3 The The Plus Blocks for Block Editor | Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to … wordfence
7d6a09f5-029a-4710-b2bd-974d0d8348b1
< 3.7.35
MEDIUM 4.3 WordPress before 5.5.2 allows CSRF attacks that change a theme's background image. wordfence
7d536acc-b297-4acd-97e2-87eae2e2b95a
< 14.9
MEDIUM 4.3 The Yoast SEO: Local plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
7d4f490e-c86e-490e-8041-36c154b890aa
< 5.3
MEDIUM 4.3 The Schedule Posts Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
7d4e685a-0462-447f-a639-4f95d5aa27ab
< 1.7.1
MEDIUM 4.3 The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. T… wordfence
7d3a6650-5be0-4162-93eb-369538a2ebc5
< 20240307
MEDIUM 4.3 The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
7d264e88-7137-48ff-8ce3-5fff77e2474a MEDIUM 4.3 The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
7d242775-3161-4e74-adb4-db4369e3cae6
< 1.2.6
MEDIUM 4.3 The Chatbox Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
7d096c3c-421b-48d8-90be-462398004a95 MEDIUM 4.3 The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Paginat… wordfence
7cffe04e-a2e5-4752-a5c1-7c95f0007e0b
< 4.9.3
MEDIUM 4.3 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
7cffdb27-c87b-467b-93d0-e92001caea9a
< 1.0.15
MEDIUM 4.3 The Trendy News theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.15… wordfence
7cfaf155-7766-4bb9-b89a-368d8adb889f
< 3.7.18
MEDIUM 4.3 wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility … wordfence
7cf70172-b8d7-4854-ab8d-f57b430ada67
< 11.7
MEDIUM 4.3 The CSS3 Compare Pricing Tables for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
7ce9bac7-60bb-4880-9e37-4d71f02ee941
< 3.16.0
MEDIUM 4.3 The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.15.1. Th… wordfence
7cd55eb6-89a9-4a30-9772-04ca90200e23
< 1.0.35
MEDIUM 4.3 The Calliope theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.33. T… wordfence
7cd4b1da-faee-4c4e-b323-e77c4c033149 MEDIUM 4.3 The Grab & Save plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.4… wordfence
7cc416cc-49a4-4752-86e7-acc52ba4f92d MEDIUM 4.3 The SendGrid WordPress plugin is vulnerable to authorization bypass via the get_ajax_statistics function found in the ~/… wordfence
7cb00342-64f9-4eeb-ba75-1c1544b11334
< 5.0.6
MEDIUM 4.3 The Product Catalog Enquiry for WooCommerce by MultiVendorX plugin for WordPress is vulnerable to cross-site request for… wordfence
7caaaaef-075b-44f6-8809-a02d5f034f26 MEDIUM 4.3 The Dragfy Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… wordfence
← Prev 1464 1465 1466 1467 1468 1469 1470 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top