πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1477 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
717ba3d3-c360-4575-aca6-a25c4147f93d MEDIUM 4.3 The Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
71463210-d65f-4a6c-ab5f-ebaafebb83e2
< 2.7.2
MEDIUM 4.3 Cross-site request forgery (CSRF) vulnerability in the Related Posts plugin before 2.7.2 for WordPress allows remote att… wordfence
713c4aac-e68a-4563-b12f-10e700a9dc65 MEDIUM 4.3 The Projectopia – Project Management Tool plugin for WordPress is vulnerable to Insecure Direct Object Reference in al… wordfence
712b0976-09a5-41d6-8f96-79006a8d41ba
< 1.1.6
MEDIUM 4.3 The Integration for Contact Form 7 and Constant Contact plugin for WordPress is vulnerable to Cross-Site Request Forgery… wordfence
71135ae7-0df5-42aa-9ede-28d684d3632c MEDIUM 4.3 The Post Featured Video plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
710f663a-c8ff-457b-8b3f-4f6601ba321f
< 1.3.2
MEDIUM 4.3 The WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) plugin for WordPress… wordfence
710ed734-ca98-4ab3-82d5-359e683ee062
< 2.9.4.1
MEDIUM 4.3 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions… wordfence
710aa0fd-34e2-4f0e-b354-0722d9692410 MEDIUM 4.3 The WP-Cirrus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.11.… wordfence
71078aaf-9803-4b46-bc94-dbcb43745629
< 2.2.6
MEDIUM 4.3 The wpForo Forum plugin for WordPress is vulnerable to unauthorized control of data due to a missing capability check on… wordfence
7102fb97-96a4-4fd9-824d-6fa6d483f37a MEDIUM 4.3 The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
71000db4-f581-44bc-8ac7-dcc5e9f9e040
< 2.0.1
MEDIUM 4.3 The Awin – Advertiser Tracking for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in ver… wordfence
70fd7ec1-b75e-4c75-b2d9-39a7fddd7339
< 2.8.4
MEDIUM 4.3 The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
70f14d9d-6ed6-4bcb-944d-f9c5aa6a17a6
< 2.8.8
MEDIUM 4.3 The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… wordfence
70eff082-be02-471e-9ee6-42a1234009b2
< 3.2.3
MEDIUM 4.3 The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for Wo… wordfence
70dda3b3-8515-49b2-8e45-21ceb9aeb419
< 5.3.10
MEDIUM 4.3 The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to u… wordfence
70dd560c-975c-4c64-a0e0-de856c5bae3a
< 4.1.2
MEDIUM 4.3 The Sticky Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.… wordfence
70d168a4-a659-4354-889e-7907215351a2 MEDIUM 4.3 The Woocommerce Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
70c8ab61-b2e2-4259-ae4b-248c139730ec
< 1.8.2
MEDIUM 4.3 The Rankie - Wordpress Rank Tracker Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
70c38363-4648-4668-bb32-14351ed7fd07
< 1.1.8
MEDIUM 4.3 The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
70b472f4-3a2d-4378-8b30-42859ec6ac39
< 14.5.0
MEDIUM 4.3 The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, … wordfence
70ae0f3e-75a8-41c7-91c0-52d672809835
< 1.0.7
MEDIUM 4.3 The Realbig plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. Th… wordfence
709dd340-7764-4c4d-892b-e07eb898df74
< 3.6.2
MEDIUM 4.3 The Textmetrics plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
70993f6f-d9b0-49d5-b35e-e129f96529f6 MEDIUM 4.3 The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
70968476-b064-477f-999f-4aa2c51d89cc
< 10.9.1
MEDIUM 4.3 The Widgets for Google Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
7092ce4a-bad9-4426-b94e-d9d688344272
< 2.4.44
MEDIUM 4.3 The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized plugin setting update due to a missing cap… wordfence
← Prev 1474 1475 1476 1477 1478 1479 1480 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top