πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1486 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
67f81b8a-ef0a-4b6d-a1ee-3e19bda6fd96
< 3.9.2
MEDIUM 4.3 The Stream plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'save_new… wordfence
67e45e8d-c0f1-42c1-9b51-4c1cadea8e48 MEDIUM 4.3 The EventON (Pro) - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized access du… wordfence
67c2cac8-c3cf-46d1-a592-229081bc31e1
< 0.9.1
MEDIUM 4.3 The Reusable Blocks Extended plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
67b7c2b5-c8ef-4659-b9e8-4c695bb76bff MEDIUM 4.3 The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to unau… wordfence
67a4fbd1-0a1c-4f07-9608-682131ccbc4f MEDIUM 4.3 The Eagle Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
67a45428-fe3a-42cf-b081-2e04415611b1 MEDIUM 4.3 The Anthologize plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0… wordfence
679e8532-e8ec-4662-b2e5-590e46f231e3 MEDIUM 4.3 The Super Store Finder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
679da7c0-98b9-4da0-bf1f-5c991e8a8111
< 1.5.1
MEDIUM 4.3 The Security Optimizer – The All-In-One Protection Plugin plugin for WordPress is vulnerable to unauthorized modificat… wordfence
67877a2e-a45d-4674-b749-05d9217ef6bf MEDIUM 4.3 The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
678608e0-2c13-4eb6-8d87-82e74c936225
< 1.2.7
MEDIUM 4.3 The LitExtension – Automated Store Migration & Import plugin for WordPress is vulnerable to Cross-Site Request Forgery… wordfence
6785be1c-85d4-48f1-be15-275c71284b3e MEDIUM 4.3 The Import External Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
67571829-1636-46b5-b43f-158c97e90811
< 4.4.3
MEDIUM 4.3 The GetGenie – AI Content Writer with Keyword Research & SEO Tracking plugin for WordPress is vulnerable to Sensitive … wordfence
6755e760-7b9b-4a90-8ce4-581ba26ee8da MEDIUM 4.3 The NetInsight Analytics Implementation Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… wordfence
6746d20c-d528-4c69-95e4-9f22d6460463
< 3.3.103
MEDIUM 4.3 The Zephyr Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
674461ad-9b61-48c4-af2a-5dfcaeb38215
< 17.0.18
MEDIUM 4.3 The Shield Security plugin for WordPress is vulnerable to Missing Authorization on the 'theme-plugin-file' AJAX action i… wordfence
6741a049-1b89-4458-86e6-aabf83915b3a MEDIUM 4.3 The Modal Survey - WordPress Poll, Survey & Quiz Plugin plugin for WordPress is vulnerable to Insecure Direct Object Ref… wordfence
673b19be-c178-4b9a-a026-e0331766f9de
< 2.0.4
MEDIUM 4.3 The Revive.so – Bulk Rewrite and Republish Blog Posts plugin for WordPress is vulnerable to unauthorized access due to… wordfence
67279c70-c416-4d18-9951-470773b9221a MEDIUM 4.3 The Woo Custom and Sequential Order Number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
66f82859-1798-42ed-bb6a-44b0af438c7f MEDIUM 4.3 The TwitterPosts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
66eeade1-d692-4c1f-a0cd-a3ea426794a1 MEDIUM 4.3 The Leader plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
66e724a1-5d40-4ba0-a324-1b4f1e463f26
< 8.2
MEDIUM 4.3 The SEOPress – On-site SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
66e5a569-1dd5-40e9-8356-d7c82c8e30ed
< 3.6.4.4
MEDIUM 4.3 The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, … wordfence
66dd73c5-1cf1-484e-b847-afe357fb2598 MEDIUM 4.3 The Xhanch - My Advanced Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
66c6a01d-35ab-496a-8457-4cd6d894f111 MEDIUM 4.3 The Filter Plus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
66c0c3e0-d7a2-4759-9e56-632ba37bf4d7 MEDIUM 4.3 The Hide Admin Bar From Front End plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
← Prev 1483 1484 1485 1486 1487 1488 1489 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top