πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1474 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
75625e6e-f75b-4e11-acd8-7388efb12b29
< 3.3.0
MEDIUM 4.3 The Asgaros Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
7561a71a-c3f0-45f1-8230-2c17cbeff916
< 20240307
MEDIUM 4.3 The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
755a6556-f1e0-45ae-a65a-6d5e20bd2b48
< 4.0.0
MEDIUM 4.3 The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
7559dfad-75cb-4ed6-b18a-2c0fc04c309a MEDIUM 4.3 The Smaily for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
7553ff69-0f56-4554-8867-9323e83dd8ce
< 3.7.4
MEDIUM 4.3 The Appointment theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.3.… wordfence
754f9598-3b41-4fe3-b290-8422031991a8 MEDIUM 4.3 The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check a… wordfence
7546b0b7-8081-4762-9e20-76dfb3c8a8a7
< 2.2.12
MEDIUM 4.3 The TK Google Fonts GDPR Compliant plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
75413c3f-7880-4b10-bf1a-fcfdab877ff5
< 1.7.73
MEDIUM 4.3 The PWA for WP & AMP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
750fc65a-081d-4c4d-ba14-73b68abd019e MEDIUM 4.3 The WordPress Image SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
750f35ce-0f1c-4a12-a7a0-2c217de277fd
< 1.18.5
MEDIUM 4.3 The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
75015eb0-3ba0-4858-b54f-151dcfe108cd
< 2.135
MEDIUM 4.3 The PW WooCommerce Bulk Edit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
74f92bd4-c752-4620-b506-d7588ff2e586
< 6.4.5
MEDIUM 4.3 The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
74f6bf42-3406-47c5-b255-6cc1e8084fb5
< 2.4.3.2
MEDIUM 4.3 The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability… wordfence
74df2a1c-c42f-4edc-9407-bf2b9b9d679b MEDIUM 4.3 The Interactive Regional Map of Africa plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
74bca579-85ec-4882-a00b-be341ce26c77 MEDIUM 4.3 The Multi Days Events and Multi Events in One Day Calendar plugin for WordPress is vulnerable to Cross-Site Request Forg… wordfence
74b6749b-a51c-4f9a-bb58-f7a9cc0205df
< 1.0.14
MEDIUM 4.3 The Ergonet Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
74b5b076-95cf-4d74-9b2d-af6a068f0490
< 2.0.5
MEDIUM 4.3 The Accessibility Tool Kit: WP Accessibility Plugin for WCAG, Section 508, ADA, EAA Compliance plugin for WordPress is v… wordfence
74b186fd-5825-4a20-829b-6b8a5ddbe853
< 1.3.9
MEDIUM 4.3 The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
74ad664d-5cfa-481c-a318-30999c43e4ac MEDIUM 4.3 The Truefy Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
74ac2b14-aea1-4366-acf4-d2d86cdec4c2
< 3.2.4
MEDIUM 4.3 The Sticky Buttons – floating buttons builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … wordfence
74a74817-30ff-42ec-9bd4-7d0638d6643c MEDIUM 4.3 The Order Delivery Date for WP e-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
7487f72c-9852-4651-a848-239d4882bbf8
< 1.5.9
MEDIUM 4.3 The Enhanced Text Widget plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing cap… wordfence
747c86f4-118b-4a9c-899c-e9067d2c7a02
< 3.13
MEDIUM 4.3 The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. … wordfence
747afa58-182a-4fb3-bfe3-f15db0b1d85a
< 6.2.0
MEDIUM 4.3 The WP SMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.1.5. Thi… wordfence
746b77c9-64f8-43e8-9c2a-ce6bc35fd24c
< 1.4.6
MEDIUM 4.3 The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to unauthorized plugin settings m… wordfence
← Prev 1471 1472 1473 1474 1475 1476 1477 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top