πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1472 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
77acb885-1776-4a74-96d0-4edbf1a92917
< 2.5.1
MEDIUM 4.3 The Product Filter by WBW plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability … wordfence
77a85024-33ff-4056-89f6-991182d71b80
< 2.12.5
MEDIUM 4.3 The Dynamic Content for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.1… wordfence
779a9f7a-4582-4d5e-bd9a-9ff7f14b452a
< 2.6.3
MEDIUM 4.3 The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for W… wordfence
7781e20b-c258-4bfd-9050-75a50a335628
< 2.2.0
MEDIUM 4.3 The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
77771c45-4a67-4c26-a679-86110459aaeb
< 4.1.05
MEDIUM 4.3 The Persian Admnin Fonts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
776de802-5748-4b71-930b-6ff9e597ed93
< 2.1.3
MEDIUM 4.3 The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
7761fe7c-e7f5-4bab-8820-42e6fcabcb2f
< 1.3.4
MEDIUM 4.3 The Ultimate Noindex Nofollow Tool II plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
77608ee4-1917-4b2c-8acf-5d6087c5ae7a
< 4.3.0.1
MEDIUM 4.3 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Insecure Direct Object Re… wordfence
775a0071-0c07-4438-918a-ff997961a6b3
< 3.8.9
MEDIUM 4.3 The Editorial Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
7759b209-4211-4ee5-ae7a-42645f5d5e96
< 13.1.0.7
MEDIUM 4.3 The Contest Gallery plugin for WordPress is vulnerable to Sensitive Data Exposure in versions before 13.1.0.7 via the cg… wordfence
774ca633-cda0-43d0-9bf9-cff181109d17 MEDIUM 4.3 The Smart Shopify Product plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability ch… wordfence
774c00fb-82cd-44ca-bf96-3f6dfd1977d0
< 2.0.5
MEDIUM 4.3 The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… wordfence
773be426-6fbc-49be-8a2a-5e794c58be8b
< 3.1.5
MEDIUM 4.3 The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object … wordfence
77397408-30a7-4be2-bc1f-505e58aafdf7 MEDIUM 4.3 The AJAX Hits Counter + Popular Posts Widget plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
7720ae0a-edeb-4e76-9bb4-4a51265d192c
< 1.3.9.4
MEDIUM 4.3 The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
770b0401-4d05-476e-a2b1-e9e9c920f5fa
< 1.1.2
MEDIUM 4.3 The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… wordfence
76f549ff-4c96-4cb4-a8c7-4967ec79727e
< 9.6
MEDIUM 4.3 The XStore theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in a… wordfence
76d10adf-5a17-49af-8ce3-f0714e8c2da6 MEDIUM 4.3 The Dashboard Notepad plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
76b8e263-7073-4f93-95cb-0b61580337b3
< 1.4.2
MEDIUM 4.3 The Send Emails with Mandrill plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
76b0eac4-de08-4f73-9897-6047374243ba MEDIUM 4.3 The Advanced Post List plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
76af3f0a-2e35-4059-960c-09769459bc01 MEDIUM 4.3 The Resize at Upload Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
76a5b421-beba-4e13-9819-350fabf459b3
< 2.0.1
MEDIUM 4.3 The Pin Generator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several… wordfence
76a52a46-fd97-4246-a4fa-e97c614c6666
< 1.12.0
MEDIUM 4.3 The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
76a1d39e-8d69-4507-b75c-d376a2122d15 MEDIUM 4.3 The Flickr Justified Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
76a0a87a-dff0-4a51-bad0-8868c342ecde MEDIUM 4.3 The User Shortcodes Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a… wordfence
← Prev 1469 1470 1471 1472 1473 1474 1475 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top