πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1484 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6a466c8f-835d-4d37-a273-7b5689dfbcea
< 1.2.27
MEDIUM 4.3 The WooCommerce Cart Abandonment Recovery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
6a423fff-7264-448e-ad97-2922a3a7151a
< 2.6.8
MEDIUM 4.3 The Wallet System for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
6a290ec5-1b31-431f-9eda-76302dc3784a
< 3.33.1
MEDIUM 4.3 The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to unauthorized acces… wordfence
6a19d494-08d1-479a-8ba4-edeb2873866a
< 1.5.6
MEDIUM 4.3 The Multi Currency For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
69d78334-2b38-43ee-acf6-c073d5826213
< 2.8.5
MEDIUM 4.3 The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This … wordfence
69c00ea4-c790-46a3-8046-b3782b02c2be MEDIUM 4.3 The Lottier for WPBakery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
69beccd3-864c-42d7-8bf9-2e9cc9f6c81e
< 1.5.9
MEDIUM 4.3 The Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator plugin for WordPress is vulnerable to un… wordfence
69bd850d-79bf-429e-b133-6caefeba7377
< 4.5.14
MEDIUM 4.3 The WPML plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.13. This… wordfence
69ad89fc-6b4a-4b21-9713-23f198e086ea MEDIUM 4.3 The CMS Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
69ab17fc-8290-4230-8c44-25d12009c08a
< 2.10.5
MEDIUM 4.3 The Paid Member Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
69a7d3fe-a873-448b-8e7a-f9e20d451be4
< 2.1.0
MEDIUM 4.3 The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
69a0d985-cc85-45ba-889d-1ed30d06f9ce
< 1.12.1
MEDIUM 4.3 The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modificatio… wordfence
699fdea9-15ae-4882-9723-9a98d7d53c74
< 3.0.0
MEDIUM 4.3 The WooCommerce UPS Shipping – Live Rates and Access Points plugin for WordPress is vulnerable to unauthorized modific… wordfence
69911634-1281-487c-87f1-37f6e4b016c9
< 12.9.0
MEDIUM 4.3 The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of … wordfence
698c8c4e-77ca-491c-bdd5-4a3d3b99b1b4
< 1.3.1
MEDIUM 4.3 The Custom WooCommerce Checkout Fields Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… wordfence
696f7c68-d19a-48ee-abc0-044f1734dfdb
< 3.7.2
MEDIUM 4.3 WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contr… wordfence
6954364e-567c-407c-afc6-983b7257cc88
< 2.0.2
MEDIUM 4.3 The Quotes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
694fe940-3d0a-4a71-99d3-bcf3a8010585
< 1.0.47
MEDIUM 4.3 The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow a… wordfence
694b05bf-7779-4365-811e-029408922ec9
< 1.7.8
MEDIUM 4.3 The Squeeze – Image Optimization & Compression, WEBP Conversion plugin for WordPress is vulnerable to Directory Traver… wordfence
69475bec-1f27-4793-8697-1132ac701c62
< 2.0.1
MEDIUM 4.3 The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.… wordfence
69430e1a-db2f-4715-84aa-5a1dfd712180
< 2.1.0
MEDIUM 4.3 The WP Job Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
6940cfbb-2592-47bf-8e73-6a7cb34ff448
< 4.11.2
MEDIUM 4.3 The WpStream – Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to Insecure Direct Obj… wordfence
69070482-772a-4df2-952a-d291ce45c72b
< 2.7.7.1
MEDIUM 4.3 The JetElements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… wordfence
68fc0a8b-b667-49fd-b015-ced27f5ccce8
< 1.7.4
MEDIUM 4.3 The WP Server Health Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
68eec693-bffe-4f3a-8e76-edf9f13093d4
< 8.6
MEDIUM 4.3 The WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to insufficient restrictions in th… wordfence
← Prev 1481 1482 1483 1484 1485 1486 1487 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top