πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1481 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6d8a5268-03a2-48c6-9c59-840a11e7a34f
< 5.0
MEDIUM 4.3 The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and includ… wordfence
6d84fa60-f780-41e2-96dc-57057c646e01
< 1.0.11
MEDIUM 4.3 The Premmerce Redirect Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
6d63e898-43e5-42b5-96b6-1453352e0cae
< 1.9.9
MEDIUM 4.3 The Bricks Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc… wordfence
6d5889f0-5e92-4be3-b0fd-ad43311e79b6
< 1.1.0
MEDIUM 4.3 The Christmas Panda plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
6d484422-4adf-4370-b228-61496d5ad78a MEDIUM 4.3 Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on … wordfence
6d43be1d-a6e7-427f-9e13-bd2fe85b3a11
< 3.0.4
MEDIUM 4.3 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to una… wordfence
6d3bb015-5a01-4450-80d3-c37d5d7d8926 MEDIUM 4.3 The Flash Video Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
6d38d457-73ad-4243-89be-6c3191ae8096 MEDIUM 4.3 The bbPress2 shortcode whitelist plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
6d2e3252-454c-47a2-a09d-5d0474c82e2b
< 4.0.1
MEDIUM 4.3 The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated use… wordfence
6d1ea80a-a1ce-4964-8dde-f3ed2df5537c
< 1.9.2.1
MEDIUM 4.3 The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress i… wordfence
6d1d541b-7010-4dbf-9b1c-d59c84390065
< 3.9.7
MEDIUM 4.3 The FlyingPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX… wordfence
6d1ba996-e26c-45cc-ab95-338663f481d9
< 3.5.3
MEDIUM 4.3 The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vul… wordfence
6d15f5de-9ec9-466d-aafe-6304356ccb39 MEDIUM 4.3 The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
6d10202f-dba6-4308-9857-a576c63ec6da MEDIUM 4.3 The Email Capture & Lead Generation plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
6d0e1c33-e6c7-4a59-87f1-37806a303b33
< 0.56
MEDIUM 4.3 The Google Authenticator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
6d03f316-542c-4128-b49d-fd2fd8609dd6
< 1.12.1
MEDIUM 4.3 The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for Word… wordfence
6cf64714-69e9-4734-b9f9-eb906a554005 MEDIUM 4.3 The Patricia Blog theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.… wordfence
6cec3472-9778-44a6-b792-306288284b0a
< 2.8.19
MEDIUM 4.3 The Brizy - Page Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and i… wordfence
6cea1c79-11db-443f-8fe8-f56276ca3516
< 2.1.6
MEDIUM 4.3 The Ever Accounting – WordPress Accounting and Invoice Plugin plugin for WordPress is vulnerable to Cross-Site Request… wordfence
6cd64ab0-007b-4778-9d92-06e530638fad
< 1.8.4
MEDIUM 4.3 The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insuff… wordfence
6ccc76fc-21c9-4188-80df-a0c14726ffc6 MEDIUM 4.3 The Availability Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
6cc709e0-870b-4d12-9ac8-55da498768a1
< 1.2.6
MEDIUM 4.3 The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
6cc52af3-8304-4536-af2c-8bc91b9fb9c9 MEDIUM 4.3 The CouponXxL theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.0. T… wordfence
6ca7ac42-2e61-498a-b46e-1f6fbdb0dd65
< 1.6.1
MEDIUM 4.3 The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPres… wordfence
6ca28c91-f75e-4691-91cf-459cc9da5ad8
< 1.0.7.5
MEDIUM 4.3 The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
← Prev 1478 1479 1480 1481 1482 1483 1484 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top