πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1470 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7a325783-3c90-4af2-a64f-7f178cea7276
< 1.0.8
MEDIUM 4.3 The MailerSend - Official SMTP Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
7a0c6425-866d-4b50-b464-87a8173c4abd
< 13.2.6
MEDIUM 4.3 The WP Statistics plugin for WordPress is vulnerable to information disclosure via the Metabox REST API in versions up t… wordfence
79fb0600-6150-4e26-b447-4414460fd62e
< 3.4
MEDIUM 4.3 The Taggbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3. This… wordfence
79e7542f-451b-4391-8367-42a1a93ceb18
< 1.6.8
MEDIUM 4.3 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Insecure Direct Object Reference in all … wordfence
79e4b7e1-9fff-4ff2-be2b-6dfa5f1ff48a
< 1.7
MEDIUM 4.3 The Invoct – PDF Invoices & Billing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data … wordfence
79e3a675-6fe9-4a22-9879-d33ed57cb4bc
< 5.2.1
MEDIUM 4.3 The Attachments plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
79d55217-f634-4fce-9f32-21d69d69c7f4 MEDIUM 4.3 The wp-gdpr-cookie-consen plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
79ba8dc8-dfc0-405a-bec0-ddc52ed3d831
< 7.13.3
MEDIUM 4.3 The Avada theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in ve… wordfence
799b1f12-05f3-4b8b-9e1f-45c676e4f2a0
< 4.0.1
MEDIUM 4.3 The Side Menu Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.… wordfence
7997ae20-88d2-4e12-87a0-a6e83808a495 MEDIUM 4.3 The WP Social Bookmarking Light plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
799779a3-8a73-4be5-a868-1d9300d847dd MEDIUM 4.3 The Menu Duplicator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
79899dc1-4953-4f95-95f5-853d24e7b9ab MEDIUM 4.3 The Just Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
7977fbfd-9864-4883-955e-3d5646763b1b
< 4.7.8
MEDIUM 4.3 The Ninja Popups plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 4.7.7. This is du… wordfence
796fb66c-5a06-4f78-b3f2-a9b0717514e0
< 3.2.8
MEDIUM 4.3 The Templately – Elementor & Gutenberg Template Library: 5500+ Free & Pro Ready Templates And Cloud! plugin for WordPr… wordfence
794d1149-5c6a-4e92-bbc9-00d718799df9 MEDIUM 4.3 The Page Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
794bc5cd-c9ac-4583-ae3d-a92361374b5f
< 1.0.9
MEDIUM 4.3 The MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, … wordfence
794b96ac-8edb-401a-8ba7-4b11fea6dde3
< 2.3.6
MEDIUM 4.3 The Vimeotheque – Vimeo WordPress Plugin & Video Gallery plugin for WordPress is vulnerable to Cross-Site Request Forg… wordfence
7945110e-2a9d-4e0e-b0e8-77c16694993b
< 1.3.13
MEDIUM 4.3 The Dynamics 365 Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
793072e9-250b-4a2c-819f-aa7e1dc7d4d6 MEDIUM 4.3 The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1.… wordfence
791e2fb0-dda2-4ae1-bfb6-0b8e66413344 MEDIUM 4.3 The Footer Contacts Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
7917c9c1-fb94-411f-85c7-b1d1c2224c5e
< 1.0.44
MEDIUM 4.3 The Recapture for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
79097eee-f76b-459e-9e7d-03013ee21695
< 5.3.16
MEDIUM 4.3 The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
7902795a-5839-4899-a7a2-e0d69e23c63a MEDIUM 4.3 The WP User Profile Avatar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
78f3c503-e255-44d2-8432-48dc2c5f553d
< 3.9.7
MEDIUM 4.3 The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the m… wordfence
78e79423-7b69-4d85-a939-96eb5385624c
< 5.3.0
MEDIUM 4.3 The WP Basic Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
← Prev 1467 1468 1469 1470 1471 1472 1473 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top