πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1478 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
705e11ff-e0c4-478a-aab2-224163357be0
< 5.6.1
MEDIUM 4.3 The PDF for Elementor Forms + Drag And Drop Template Builder plugin for WordPress is vulnerable to unauthorized access d… wordfence
70587bb9-6f76-4073-b5db-06ffda0194e9
< 7.8.8
MEDIUM 4.3 Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation. wordfence
7058306f-ec20-4722-aaa1-552a75945a1e MEDIUM 4.3 The A no-code page builder for beautiful performance-based content plugin for WordPress is vulnerable to Cross-Site Requ… wordfence
70493df9-82b8-4160-8d75-889fada7541f
< 3.9.6
MEDIUM 4.3 The Simple Download Monitor plugin for WordPress is vulnerable to Log Resets in versions up to, and including, 3.9.5. Th… wordfence
70352973-5fa7-40b0-9e07-eab2e96520b7
< 3.7.26
MEDIUM 4.3 Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPres… wordfence
702aa972-7b74-4417-8d33-a26c3831934f
< 1.2.4
MEDIUM 4.3 The Ever Compare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.… wordfence
701bf711-d692-4eb1-8459-befa62264b97 MEDIUM 4.3 The Fontiran plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. Thi… wordfence
7006aa50-8fcf-46ad-921b-b47cbdb7d9e3 MEDIUM 4.3 The WP Page Post Widget Clone plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
6ff04e98-6c41-4117-8148-9c85b6aaf7d4 MEDIUM 4.3 The OneStore Sites plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.… wordfence
6fd87d34-2e7f-4c75-8816-b39820309077
< 3.0
MEDIUM 4.3 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulner… wordfence
6fd866ac-6094-4f76-9fba-69494381214c
< 2.4.22
MEDIUM 4.3 The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
6fd6abf1-57f8-41f2-b890-ccac6f96569f MEDIUM 4.3 The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Cross-Site Reque… wordfence
6fcfd395-ccda-4025-8d3b-ccc3a7062b6d
< 3.1.0
MEDIUM 4.3 The Asgaros Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.0… wordfence
6fb7944a-58ad-4e52-8fe2-6b535517541e MEDIUM 4.3 The Knowledge Base – Knowledge Base Maker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
6fb79409-441a-4991-bc0d-c0f46eb72bb9
< 2.3.6.21
MEDIUM 4.3 The Swift Performance Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
6fb1dd3d-1695-44e9-b8df-e559e53f99b0
< 1.7.2
MEDIUM 4.3 The Open Shop theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
6fa70ddc-9a5c-4001-967a-5aad789c862c
< 4.9.5
MEDIUM 4.3 The WP Links Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.9… wordfence
6fa5566f-b814-4173-8f7d-9a514397d653
< 4.9.8
MEDIUM 4.3 The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulne… wordfence
6fa1299e-308e-47ea-843c-c76b8a412ce9
< 7.6.11
MEDIUM 4.3 The wpDiscuz plugin for WordPress is vulnerable to Arbitrary Content Injection in versions up to, and including, 7.6.10.… wordfence
6fa02ba1-ab10-4a2b-a504-891d416bb1d8 MEDIUM 4.3 The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
6f8a2bb9-5310-4a1f-b21c-253e3d0cb74d MEDIUM 4.3 The WP Favorite Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
6f8814b0-6818-47c2-9f2a-8fe12485bd33
< 1.13.7
MEDIUM 4.3 The Elementor Addon Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabili… wordfence
6f854ffc-244b-45c3-94ce-198e85c11869
< 28.0.1
MEDIUM 4.3 The Contest Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
6f8437a8-a034-40b8-bc61-d5c495865cbd
< 3.19.8.1
MEDIUM 4.3 The WPPizza – A Restaurant Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
6f810102-cf25-4898-a3a6-3cdc9a96aaea
< 8.3.1
MEDIUM 4.3 The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing cap… wordfence
← Prev 1475 1476 1477 1478 1479 1480 1481 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top