πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1468 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7c9e5fb6-5a78-4890-8cc4-2b9e417ff903
< 2.5.3
MEDIUM 4.3 The Internal Links Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
7c7f6ef2-6c50-4739-8844-0db7d9ffe7f7
< 1.5.5
MEDIUM 4.3 The MC Woocommerce Wishlist plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
7c7115f9-a0b0-43ed-9153-a9fe87176e4e
< 1.59
MEDIUM 4.3 The exit-strategy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
7c66894a-8d0f-4946-ae4d-bffd35f3ffb7
< 1.7.2
MEDIUM 4.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
7c5ba00f-f5ec-42d9-8f30-9ce30a94fb0d
< 2.3.1
MEDIUM 4.3 The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc… wordfence
7c35e20f-bfb0-4de0-9f8f-6e04fbbe138a MEDIUM 4.3 The Team Builder – Meet the Team plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
7bf04825-8f98-4f4f-ab09-a2e4caa9c2ee MEDIUM 4.3 The WP Business Hours plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
7bcfb35d-6d86-4481-be97-58c2c410e0cd MEDIUM 4.3 The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to un… wordfence
7bc142c3-6c80-49e2-9274-a211c8cc736f
< 3.1.6
MEDIUM 4.3 The Quick Interest Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
7bb377a9-fd31-4e1e-97d0-b764acba3122
< 2.0.8
MEDIUM 4.3 The Zoho Campaigns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
7bb1be6d-5af9-4b58-a641-05a913548fe7 MEDIUM 4.3 The BadgeOS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1.6. … wordfence
7ba3b72b-67a6-4f7c-adcd-6ce39663cda5 MEDIUM 4.3 The payOS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.61. Thi… wordfence
7ba2b270-5f02-4cd8-8a22-1723c3873d67
< 6.5.2.5
MEDIUM 4.3 The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
7b8b111a-9626-41f4-8a13-51f576af0257
< 3.9.4
MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course complet… wordfence
7b8ab7f8-a10c-4acb-887a-6c5c4055d526
< 2.9.50
MEDIUM 4.3 The Affiliates Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
7b899c03-e5f0-485d-accf-15acfd4e1b0c
< 1.6.10
MEDIUM 4.3 The TeraWallet - Wallet for WooCommerce plugin for WordPress is vulnerable to unauthorized access in versions up to, and… wordfence
7b8483b8-07b4-436f-992f-35e16fef867b
< 1.5.12
MEDIUM 4.3 The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
7b7c9123-a918-4fc0-9b16-f537b418b990 MEDIUM 4.3 The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
7b78004e-caa5-4478-ba16-5f1a10e31541
< 2.0.3
MEDIUM 4.3 The DX Delete Attached Media plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… wordfence
7b6db928-f8ff-4e78-bfc7-51f1d1ccd1fa
< 2.3.8
MEDIUM 4.3 The Clone plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t… wordfence
7b67f7e4-d431-4185-9509-217f6e22c98b MEDIUM 4.3 The Advanced Google Universal Analytics plugin for WordPress is vulnerable to unauthorized access of data due to a missi… wordfence
7b509887-6d32-4e7f-bdff-fd4f6c76f6f2
< 3.7.4
MEDIUM 4.3 The Ni WooCommerce Sales Report plugin for WordPress is vulnerable to unauthorized access of data due to a missing capab… wordfence
7b26e5f7-bd35-4412-a608-9cdfeff0b025
< 1.7.7
MEDIUM 4.3 The WP Event Aggregator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
7b121abf-3842-43ac-a3dc-bde6d5e0b263
< 2.0
MEDIUM 4.3 The Export Media URLs plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
7b093135-5eed-41b8-8c90-8217bb9a90a1
< 3.4.1
MEDIUM 4.3 The Conditional Shipping for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
← Prev 1465 1466 1467 1468 1469 1470 1471 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top