πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1469 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7b039c23-51d4-422a-a57b-59abaeca682c
< 3.0.0
MEDIUM 4.3 The WPAdmin AWS CDN plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
7b026b30-5a1b-4551-93a4-0c0cdbac650b MEDIUM 4.3 The GB Gallery Slideshow plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
7ae17154-bd68-4260-9b3a-bb73f2a70694 MEDIUM 4.3 The MF Gig Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
7ada8d4d-124d-4c8e-be4c-a80ee8c867f6
< 8.6.13
MEDIUM 4.3 The MapSVG plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
7ad25948-3265-4c4c-9b99-86f7240600ce
< 12.4.15
MEDIUM 4.3 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … wordfence
7acbcf74-2bae-412b-bf9d-70287a91deea
< 2.5.3
MEDIUM 4.3 The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5… wordfence
7ac68314-c704-4273-addc-4bc623659769 MEDIUM 4.3 The Charity Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in… wordfence
7ac5e363-e1ae-4bab-b94f-73365c35e67d MEDIUM 4.3 The Nokri theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This … wordfence
7abf5f68-2a5f-4cdf-90cf-38dd7189b8c9 MEDIUM 4.3 The Title Experiments Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
7abf08c2-0b2f-48cd-a438-69c66dbc0238 MEDIUM 4.3 The Custom Bulk/Quick Edit plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
7ab4517e-8dd8-47a8-8e03-d3e0fd991820
< 1.7
MEDIUM 4.3 The Bard - A Theatre and Performing Arts WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery… wordfence
7aa0bb19-4f06-4e16-bdd0-7cb125d5dfe2 MEDIUM 4.3 The WP-GeSHi-Highlight β€” rock-solid syntax highlighting for 259 languages plugin for WordPress is vulnerable to Regex … wordfence
7a9e129c-05e2-46b8-9bdd-2e986977591a MEDIUM 4.3 The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
7a9a1605-6f62-445d-bd20-eeec0767d894
< 2.0.9
MEDIUM 4.3 The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
7a8eda88-c45a-4867-b427-d63b586e6de3
< 2.11.0
MEDIUM 4.3 The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerabl… wordfence
7a8c4232-2e1e-4c99-83d5-d70f7ca1c879
< 2.4.0
MEDIUM 4.3 The Stamped.io Product Reviews & UGC for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery du… wordfence
7a87f248-a613-44c5-aebc-970a8161ffba MEDIUM 4.3 The Custom Author Base plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
7a874287-c648-4807-8387-b0b47187651e
< 4.7.0
MEDIUM 4.3 The Hotel Booking Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
7a830d58-14e8-4929-a0f8-08ee4efae340 MEDIUM 4.3 The FL3R FeelBox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.1.… wordfence
7a71c1e1-c0f5-4b11-9f15-02ac22e4a376
< 3.4.11
MEDIUM 4.3 The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is … wordfence
7a6c16dd-3681-4867-b608-5501ff9e9331
< 1.9.3
MEDIUM 4.3 An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possib… wordfence
7a69cc6e-cbb7-4b66-8a55-709e29273378
< 4.1125
MEDIUM 4.3 The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to unauthorized ac… wordfence
7a54b803-7e30-4964-88f0-d79276e67218
< 4.3.8
MEDIUM 4.3 The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
7a44d182-2a43-47c0-ab2e-36c0514c1d47
< 5.8.7
MEDIUM 4.3 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modificatio… wordfence
7a4332a2-b26e-43b8-be4a-50ac54a1ab2b MEDIUM 4.3 The ConsultStreet theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
← Prev 1466 1467 1468 1469 1470 1471 1472 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top