πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1479 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6f789ff9-5d86-4911-8b2f-2a425393c61d
< 3.11.0
MEDIUM 4.3 The FunnelKit Checkout plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… wordfence
6f7386bf-3968-46b8-9c47-5fbc41801e04
< 6.3.1.2
MEDIUM 4.3 The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable t… wordfence
6f69d100-b737-430c-a7cd-33901db18e25
< 3.0.0
MEDIUM 4.3 The NikanWP WooCommerce Reporting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
6f643ffe-a904-47fd-9f76-01acacfebef9 MEDIUM 4.3 The SMTP Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.49.… wordfence
6f5c4194-4f97-4f85-af90-e983ba9ce3a6 MEDIUM 4.3 The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing ca… wordfence
6f593dce-4b56-46c0-becd-75fd16f165a8 MEDIUM 4.3 The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable… wordfence
6f52fbbb-5ef0-438f-80a6-7ef64fae9fe6
< 2.14.4
MEDIUM 4.3 The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to unauthorized access due t… wordfence
6f4424be-d63d-431d-a237-2bff6c4a647a
< 1.2.2
MEDIUM 4.3 The Restaurant and Cafe theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
6f2b3c4a-8dc5-459b-ae55-d11fc988dbe8
< 1.33.2
MEDIUM 4.3 The WPS Bidouille plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
6f26b04f-2a25-40a6-9b2c-27d9970acb8f
< 2.3.4
MEDIUM 4.3 The HT Mega plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. Th… wordfence
6f24c2f1-be36-4d64-8f2e-ce27dfc697e3
< 2.4.5
MEDIUM 4.3 The RapidLoad plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the rapidlo… wordfence
6f21955b-1fd2-4d92-acfd-07fc1ff194fa
< 5.6.0
MEDIUM 4.3 The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
6f1e3586-99f7-4cac-bbb2-1a6406c4f8a4
< 2.3.0
MEDIUM 4.3 The Performance Lab plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
6f1345b0-a43e-475f-9d19-78600f17b8e6
< 3.9.7
MEDIUM 4.3 The ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerabl… wordfence
6f036c2d-eaa4-4b1a-a58b-18aa9a9cc9bd
< 6.3.7
MEDIUM 4.3 The The Plus Addons for Elementor Page Builder Pro plugin for WordPress is vulnerable to unauthorized access due to a mi… wordfence
6eed4626-1fa5-49b1-864e-c37e4cf58ad8
< 5.7.3
MEDIUM 4.3 The wp-media-folder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
6ed96d76-ef7d-46c5-a164-992dd4f15afe
< 3.6.21
MEDIUM 4.3 The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … wordfence
6ed7184d-de43-4f2f-ae49-1aecd717f8b9 MEDIUM 4.3 The Tidy Up plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3. This… wordfence
6ed605a1-9544-4b53-8d62-ad89214a4fb8
< 4.8.6
MEDIUM 4.3 The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
6ed5add1-d2d9-44ae-9190-7a564bd31f57 MEDIUM 4.3 The PayPal Express Checkout plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
6ece7e74-ffd9-48f9-b66b-58708233b24b
< 3.0.2
MEDIUM 4.3 The Vitepos plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
6ec3051e-a5e4-48ee-8f8e-eb5dbc482f33
< 3.4.2
MEDIUM 4.3 The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
6eb0aa16-a269-4297-861f-6bad88066c68
< 6.4.7
MEDIUM 4.3 The Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versio… wordfence
6ea4ad81-dba6-4055-b81c-682424a6ffd0
< 5.0.1
MEDIUM 4.3 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access due to … wordfence
6ea07ba1-9d0c-4c90-9eb2-d6f1a573dca2
< 4.2.6
MEDIUM 4.3 The Ultimate Auction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
← Prev 1476 1477 1478 1479 1480 1481 1482 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top