πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1483 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6b7ad031-e15b-4315-9905-9f258f7c4ade
< 3.4.34.1
MEDIUM 4.3 In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to tri… wordfence
6b66a0bc-9125-45ee-9583-bc503634a0ce MEDIUM 4.3 The Plugin updates blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
6b665b86-6969-4458-b881-6236a4bb259d
< 3.8.2
MEDIUM 4.3 The SALESmanago plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.1… wordfence
6b60777e-6e07-42bd-9364-43367e209227
< 1.0.3
MEDIUM 4.3 The User Sync – Remote User Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
6b591f0e-f9bb-4bbc-988c-7a0b03cdd1c7
< 1.5.1
MEDIUM 4.3 The Product Code for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
6b53ed24-2821-440f-9aba-69d75b7459a3 MEDIUM 4.3 The Custom User CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
6b524fc5-4beb-49f6-bafa-c788c6d1d78c
< 7.0.0
MEDIUM 4.3 The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
6b4a3ed0-50e9-4bc3-a003-17b5d7c15848 MEDIUM 4.3 The Cryptocurrency Widgets Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
6b3e93bf-af5c-4ca3-a531-2d91df880c51
< 2.9.2
MEDIUM 4.3 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to… wordfence
6b36938e-5333-4331-9bb1-34465fe03f2f
< 2.9.9
MEDIUM 4.3 The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… wordfence
6b2971f0-e989-4e2e-9207-05cd381786ce
< 1.2.12
MEDIUM 4.3 The Stockie Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
6b26093a-ffb8-4d22-add1-eecd94f88129
< 6.0.3
MEDIUM 4.3 The Advanced Custom Fields plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and includin… wordfence
6b1524f3-1c59-49a1-bbe3-94dcfd232b1d
< 2.6.0
MEDIUM 4.3 The WP Discourse plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5.9.… wordfence
6b00a274-4c77-429f-9d06-72c82094c838
< 2.3.3.1
MEDIUM 4.3 The Sign-up Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
6affdb56-39cc-4749-b7cb-b80b7666f028
< 2.2.0
MEDIUM 4.3 The GenerateBlocks plugin for WordPress is vulnerable to information exposure due to missing object-level authorization … wordfence
6af64b51-1758-495f-b6d7-364488de9ab8
< 4.5.9
MEDIUM 4.3 The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a … wordfence
6af0aa17-2bbf-489e-aedb-95b514f6c9a2
< 4.3.0
MEDIUM 4.3 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Insecure Direct Object R… wordfence
6af02955-2ea4-459a-bea7-ecbe35232ec5
< 1.3
MEDIUM 4.3 The Ashe Extra plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ashext… wordfence
6aec878b-79c6-45da-a8f7-0f2d3185ecc2 MEDIUM 4.3 The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
6adc0154-169a-4d72-8687-66dbf6766139
< 1.6.0
MEDIUM 4.3 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
6abd3968-a8e7-4b40-bb7e-387bab10eba9 MEDIUM 4.3 The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cr… wordfence
6a9285fb-fc4e-4ea4-89d5-f376f03c54a4
< 5.4.0
MEDIUM 4.3 The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 5.3.2… wordfence
6a8c5d9b-4535-4edb-a92e-a9b83a0d22c3
< 1.1.5.4
MEDIUM 4.3 The Hostel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5.… wordfence
6a5db3fc-6ae4-4566-8610-687cb725cf6e MEDIUM 4.3 The School Management System – SakolaWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
6a5ad100-2522-41f0-a1d5-8e8d828afecd MEDIUM 4.3 The SpeakPipe – Voicemail for Websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
← Prev 1480 1481 1482 1483 1484 1485 1486 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top