🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1480 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6e9f6d07-5ba5-48ad-bfcc-084913436b39
< 1.3.7
MEDIUM 4.3 The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versi… wordfence
6e8d038d-8e2d-442d-932d-0fd31a8c501c
< 2.34.3
MEDIUM 4.3 The Download IP2Location Country Blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
6e739eb4-6b8b-4bc7-a1e6-790180668c93
< 3.6.0
MEDIUM 4.3 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized … wordfence
6e738f35-a691-4f82-8be3-92215e26aed3 MEDIUM 4.3 The Woocommerce Advanced Product Organizer – Dynamic Sorting & Reordering plugin for WordPress is vulnerable to unauth… wordfence
6e6603a0-8f35-49fb-a517-ba6344538c4d
< 4.9.9
MEDIUM 4.3 The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private … wordfence
6e58d0e1-151e-4f94-b9ee-c91a19c241eb MEDIUM 4.3 The Genemy - Creative Minimal Landing Page Builder for Digital Startup Design Studio Agency in Marketing theme for WordP… wordfence
6e3bf81a-cfc3-4203-9534-8a70f1fbc316
< 2.4.2
MEDIUM 4.3 The Visual Link Preview plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … wordfence
6e385a61-a6c7-41a8-b0f4-619055b66b3a
< 1.0.30
MEDIUM 4.3 The Highlight theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.29. … wordfence
6e29fd6b-462a-42be-9a2a-b6717b20a937
< 4.5.2
MEDIUM 4.3 The WP Activity Log Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
6e273662-935f-45ad-b424-612da0799eba
< 3.1.2
MEDIUM 4.3 The Landingi Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
6e1b7f09-f5b8-46a2-bbbe-7ee192f11c12 MEDIUM 4.3 The Breaking News WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
6e031c1d-14c9-4e5d-8881-2f02ee321efe
< 4.1.37
MEDIUM 4.3 The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauth… wordfence
6e02e94f-e0f4-4a6a-9670-702b2d0a78c1 MEDIUM 4.3 The Page Title, Description & Open Graph Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
6e02d105-0f1e-479e-a537-7a7fdbbd7804 MEDIUM 4.3 The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
6def0fd7-4b48-4c2c-935a-f76290bc01e0
< 1.9.2
MEDIUM 4.3 The ووسلام – همگام سازی ووکامرس و باسلام plugin for WordPress is vulnerable to Cross-Site… wordfence
6de3dfaa-4bf8-49a3-8409-7ef2d37a38cd MEDIUM 4.3 The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
6ddf6da6-ec71-4206-8798-2c0c751b3209
< 2.0.12
MEDIUM 4.3 The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plu… wordfence
6dd8a804-a2bf-430a-8cd5-90e797ddba21
< 16.1
MEDIUM 4.3 The WP Google Review Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
6dc3f308-d1e1-430b-bccd-168c0972fe7c
< 2.5.35
MEDIUM 4.3 The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modifica… wordfence
6dc25c27-e3a8-4d69-9468-734fef450719
< 1.4.114
MEDIUM 4.3 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access due… wordfence
6db5f214-ba1a-4528-9bb6-0592822bf8bb
< 1.4.1.8
MEDIUM 4.3 The WOOCS – WooCommerce Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
6dafc81c-f1be-422d-b34f-87f1956e8849 MEDIUM 4.3 The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
6d9eb54f-4ff2-49d6-94d7-73aa75edb97b
< 3.2.12
MEDIUM 4.3 The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
6d96f6ef-9366-41b8-9420-fbddf270209a
< 6.1.3
MEDIUM 4.3 The Advanced Custom Fields: Font Awesome Field plugin for WordPress is vulnerable to unauthorized access due to a missin… wordfence
6d8b57de-d02c-40c0-abdb-ff490bcf429e MEDIUM 4.3 The Time Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
← Prev 1477 1478 1479 1480 1481 1482 1483 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top