πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1482 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6c8b8b0a-2d84-499b-8646-0a84e47620e7
< 10.9.1
MEDIUM 4.3 The Salon Booking System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a… wordfence
6c72645a-dac5-473b-9ac4-75dbd2643fa1 MEDIUM 4.3 The WP Bulk Post Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
6c71183f-45e7-44de-a957-614ce417db90 MEDIUM 4.3 The Vrm 360 3D Model Viewer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and … wordfence
6c68e8a1-926f-497f-b9f2-b0a67cd09adf
< 1.1.23.1
MEDIUM 4.3 The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc… wordfence
6c67aefd-5da3-437e-bd7b-1f4dbea3130f
< 3.12.28
MEDIUM 4.3 The Easy Appointments plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
6c5cffd0-3674-48de-9b4a-481815f3e730
< 1.6
MEDIUM 4.3 The Multilang Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
6c4a9092-fd49-42fe-a84d-a9f7fe708122
< 1.2.0
MEDIUM 4.3 The Stock Exporter for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
6c43b9b4-4394-428a-b381-d6a776fcd130
< 1.3.3
MEDIUM 4.3 The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerabilit… wordfence
6c4357a3-ef54-4843-a9ea-b1f86f542e06
< 1.4.0
MEDIUM 4.3 The Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow plugin for WordPress is vulnerable to u… wordfence
6c3fe739-eed0-432c-8608-50dc08ef1456
< 1.3.5
MEDIUM 4.3 The Reviews Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… wordfence
6c3852d2-6a14-4132-8010-f93b606ee079
< 4.4.8
MEDIUM 4.3 The LiveAgent – Omnichannel Help Desk & Live Chat Software plugin for WordPress is vulnerable to Cross-Site Request Fo… wordfence
6c369971-1ae2-4e26-80cc-cf25d25a310e
< 1.1.8
MEDIUM 4.3 The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized… wordfence
6c2843b5-9b03-48f0-9084-648edcad8670 MEDIUM 4.3 The CF7 Spreadsheets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
6c0c40f5-44ac-4e31-a73d-50aeefc541be
< 1.10.5
MEDIUM 4.3 The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to unauthorized acce… wordfence
6c00e07a-7a0b-4cfa-8f6b-b03e3b485f07
< 2.6.4
MEDIUM 4.3 The New User Approve plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… wordfence
6bfd7bfa-acd4-4a60-8ece-6922d6ad63e5
< 6.3.1
MEDIUM 4.3 The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized access due to a … wordfence
6bf6b5fd-34d3-4f75-a50f-02b81a9ec0dc
< 7.0.3
MEDIUM 4.3 The WPJAM Basic plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7… wordfence
6bef4137-c188-4dae-b6fc-5485cfa216c4
< 12.4.08
MEDIUM 4.3 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
6bea6a77-79e8-4d3a-bd3e-2bb3d20b6fe9
< 4.1.39
MEDIUM 4.3 WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.3.1 via the comments … wordfence
6bceb15e-0727-4bd5-b4e7-f2c1f2f3ef51
< 3.0.18
MEDIUM 4.3 The License Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in all versions up … wordfence
6b978749-7ea5-45f4-9f69-66a19c0e39ca
< 4.5.4
MEDIUM 4.3 The WP Meta SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.3… wordfence
6b8ffdb9-b8c6-428c-a047-8e5286b2c2fb
< 5.9.8.3
MEDIUM 4.3 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
6b8fac8f-619a-442e-8b8f-43a0c0a44b07
< 2.9.0
MEDIUM 4.3 The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… wordfence
6b83527a-aedd-4cc5-9416-1cbdfc2b8850
< 2.6.10
MEDIUM 4.3 The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
6b7ce040-32b7-4440-be4f-d33fe9c49e51
< 4.7.0
MEDIUM 4.3 The Simple Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
← Prev 1479 1480 1481 1482 1483 1484 1485 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top