πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1485 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
68e6675e-b9f4-41e5-8ebf-abab53f5d542
< 1.5
MEDIUM 4.3 The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could … wordfence
68d168fb-9f28-48b2-a054-d279d4cd21c3
< 1.2.7
MEDIUM 4.3 The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
68cc2aec-f21d-482d-a8bd-bbc60f593cb5 MEDIUM 4.3 The flickrRSS plugin 5.3.1 for WordPress has CSRF via wp-admin/options-general.php. This makes it possible for unauthent… wordfence
68c93ccb-4da8-4615-b596-5af93f55c8d7 MEDIUM 4.3 The ACME Divi Modules plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
68c28402-b8b2-4efb-8725-e344d663703c MEDIUM 4.3 The wordpress related Posts with thumbnails plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
68b8167f-808c-4401-bed5-14088b0c1418
< 4.5.1
MEDIUM 4.3 The WP Easy Pay – Payment and Donation Form Builder for Square plugin for WordPress is vulnerable to unauthorized acce… wordfence
68a8a277-2ea6-4d75-b8cd-4d20eb17b3aa MEDIUM 4.3 The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
689ed1b8-8ef9-4994-8a39-9e0b079aed9a
< 3.1.4
MEDIUM 4.3 The WP ADA Compliance Check Basic – Most Comprehensive Web Accessibility Solution for WordPress plugin for WordPress i… wordfence
689abb68-0c19-4f89-91db-fd15ab8bca8e
< 5.0.22.decaf
MEDIUM 4.3 The Event Espresso 4 Decaf – Event Registration Event Ticketing plugin for WordPress is vulnerable to limited unauthor… wordfence
6895a774-7e78-4ab2-a2b3-2a333f258778 MEDIUM 4.3 The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to an… wordfence
689511e0-1355-4fcb-8a72-d819abc8e9a3
< 2.0
MEDIUM 4.3 The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficie… wordfence
689140fb-c952-4c51-96a4-60ed2b125d60 MEDIUM 4.3 The TS Demo Importer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
68721ded-0a80-4cff-aaf0-59b2fcf67456
< 5.2.16
MEDIUM 4.3 The Ultimate Product Catalogue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
6864382e-7a45-413c-a80e-a5dd827fe6c7
< 1.64.1
MEDIUM 4.3 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
6859b917-f1a4-4444-8775-e2e9371c8506 MEDIUM 4.3 The mLanguage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6… wordfence
685408e9-7e32-4e48-8517-cefa1d33c4fc MEDIUM 4.3 The Leyka plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in a… wordfence
68504f49-0b18-4010-97b0-7e7391408d36
< 9.5.8
MEDIUM 4.3 The Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) plugin for WordPress is vulne… wordfence
684de9c5-6f94-455d-b095-9f2df733ab95 MEDIUM 4.3 The IMAQ Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2… wordfence
6840c91f-a5d9-4940-8a08-d62acc5d43eb
< 7.0.6
MEDIUM 4.3 The Themify Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7… wordfence
683131a0-eec3-4251-b322-5c2088855687
< 4.2.4
MEDIUM 4.3 The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to unauthorized access of functionality due to a… wordfence
682ec57a-f67c-40a9-91cd-2a11159ff695 MEDIUM 4.3 The LLM Hubspot Blog Import plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
68141f7e-9a87-4455-bd9f-e57277d4efa7
< 5.0.9
MEDIUM 4.3 The Dokan plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.8… wordfence
6811abba-69a6-49c9-87e6-178b6788890d
< 1.4.110
MEDIUM 4.3 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Cross-Site Request Forg… wordfence
6800fec4-fd05-46d6-b179-018113308ab2
< 4.19.2
MEDIUM 4.3 The Real 3D FlipBook plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
67ff1f6e-0bea-4e09-ac3d-727d13fcbfa1
< 2.3.2
MEDIUM 4.3 The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Insecure Direct O… wordfence
← Prev 1482 1483 1484 1485 1486 1487 1488 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top