πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1473 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7699f741-b743-4fe7-9acb-d81d4da711ce
< 3.6.0
MEDIUM 4.3 The Real Estate 7 WordPress theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
76820ffd-5f35-46d0-b54a-2488ee96ee7a
< 5.29.0.1
MEDIUM 4.3 The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up… wordfence
7678b80f-3184-4979-b1f4-25cd75836010
< 2.1.7
MEDIUM 4.3 The LWS Hide Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
7673b2ba-5d7a-4ae9-92e7-1a910687fdb8
< 2.4.41
MEDIUM 4.3 The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin… wordfence
7660c8ce-3215-4ecc-8c94-9750878cb37c MEDIUM 4.3 The No Spam At All plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
764aec73-f291-4372-9dde-812ffaf025ed
< 4.5.4
MEDIUM 4.3 The WP Meta SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.3… wordfence
763fec04-72c5-4910-af97-f58b5b69a02e
< 1.4.17
MEDIUM 4.3 The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
763a7dec-72e3-46d2-a82e-268c577e0289
< 2.9.12
MEDIUM 4.3 The Post SMTP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the regener… wordfence
762be203-b4bb-4618-9916-1ed4f33dbe2e
< 14.16.10
MEDIUM 4.3 The Statistics plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 14… wordfence
760f7736-db49-4210-a2f3-3abb506106d7
< 3.15.6
MEDIUM 4.3 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… wordfence
760e12f5-4af5-4fe6-a97c-350f75961b70
< 1.2.3
MEDIUM 4.3 The GLB theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in vers… wordfence
75ec04f1-8bea-4514-b1d0-da5b305219d7
< 2.5.2
MEDIUM 4.3 The Brizy – Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
75ddf732-ddb2-47ba-884a-477fcc6595b4 MEDIUM 4.3 The Replace Word plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.… wordfence
75d5c684-090e-4fff-9bf7-2b7c41ef95d3
< 3.4.6
MEDIUM 4.3 The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecu… wordfence
75cc5088-9376-4b9a-bc1e-83269e9652fa
< 1.4.2
MEDIUM 4.3 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
75c5d4e6-9ef3-4b12-9ee9-67121dbb0fcd
< 2.2.2
MEDIUM 4.3 The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, an… wordfence
75ba69c5-9e1d-4644-b28c-069c904798cc MEDIUM 4.3 The WP Multistore Locator β€” WP Store Locator Plugin: Effortless Integration With Snazzy Maps plugin for WordPress is v… wordfence
75b92908-83cc-4189-995f-5dcea44fe8f7
< 1.5
MEDIUM 4.3 The Child Theme Wizard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
75b26ed9-3250-40c9-849c-f76d8d435b1a MEDIUM 4.3 The Tax Exempt for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including… wordfence
75a90089-2198-459e-86a4-eb7937bd223f MEDIUM 4.3 The Unsafe Mimetypes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
759bb4c0-2d51-49d3-9132-6a2a246cebc0
< 1.2
MEDIUM 4.3 The DN Shipping by Weight for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
7598e56d-a60f-4caa-86de-db731079f538 MEDIUM 4.3 The Orders Chat for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
758a4b81-4c34-4a01-a0ef-eaa60555fb29 MEDIUM 4.3 The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
757e41dd-d72f-4e87-a087-c5c38bd727e5
< 1.7.8
MEDIUM 4.3 The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due … wordfence
757690b0-6c59-4e74-aad2-f5fde9f7a2fb
< 2.0.9
MEDIUM 4.3 The MailerLite – WooCommerce integration plugin for WordPress is vulnerable to unauthorized modification of data due t… wordfence
← Prev 1470 1471 1472 1473 1474 1475 1476 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top