πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1487 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
66bc83f5-0f6c-425f-a560-e79e777b76ca MEDIUM 4.3 The WooCommerce Order Status Change Notifier plugin for WordPress is vulnerable to unauthorized modification of data due… wordfence
66b59837-b0e6-4bab-b7b6-7c3510164f04
< 2.1.60
MEDIUM 4.3 The Job Board Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
66b5662a-0be7-43f5-b055-02b3cd3a44d1
< 3.29.11
MEDIUM 4.3 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
66ac51f9-3571-4e07-a110-afec43abab37
< 2.0.6
MEDIUM 4.3 The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to unauthorized modification of data d… wordfence
66a5a011-4c2f-4da9-9b17-96af830ba880 MEDIUM 4.3 The Nictitate theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. T… wordfence
669f5363-22af-4526-b375-3cca2b1db0ec MEDIUM 4.3 The Jazz Popups plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.7… wordfence
669b0f30-8958-420c-93c5-0103b71967dd
< 6.18.16
MEDIUM 4.3 The Website Builder by SeedProd β€” Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for W… wordfence
66988357-af1a-4763-b814-9092b86e51ef
< 2.4.1
MEDIUM 4.3 The PDF Poster plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
669833b3-1689-4051-8990-c6eddae4858f
< 3.1.1
MEDIUM 4.3 The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … wordfence
66889a85-07d9-4d0f-ac16-31bb9d2d974a MEDIUM 4.3 The Constructo theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.9. … wordfence
6677813d-1441-41c7-bd2d-859b79260c87 MEDIUM 4.3 The Popping Sidebars and Widgets Light plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
6670b07e-c9ff-468c-8bfe-603d21bb9afb
< 1.1.6
MEDIUM 4.3 The Coachify theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5… wordfence
6669d04c-9f97-43a5-a312-1cb3d67d21fa
< 3.4.2
MEDIUM 4.3 The Rate my Post - WP Rating System plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions u… wordfence
66585943-cb70-4296-af66-5b786d1bafb9
< 1.23
MEDIUM 4.3 The reCAPTCHA for all plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capabil… wordfence
663d7ec3-5e95-41c9-aced-18756907f2db
< 2.7.4
MEDIUM 4.3 The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
66377ee2-cc87-4cfe-a4e4-cef4459bf2ec
< 1.4
MEDIUM 4.3 The Seraphinite Alternative Slugs Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
66363035-c09f-4b41-b9fe-2e2bdd851f41
< 1.9.2.2
MEDIUM 4.3 The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Information Exposure in all versions up … wordfence
662f6ae2-2047-4bbf-b4a6-2d536051e389
< 1.6.44
MEDIUM 4.3 The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to… wordfence
66294c25-d715-42f2-b249-5ef68ae92cca
< 5.04
MEDIUM 4.3 The Dynamic Post plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
6625dcea-13cc-4c08-9361-946638bf6678
< 3.9.8
MEDIUM 4.3 The Tutor LMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
660d4214-999f-4a4f-9a7e-332163b9867b MEDIUM 4.3 The Pro Bulk Watermark Plugin for WordPress plugin for WordPress is vulnerable to Path Traversal in all versions up to, … wordfence
66095908-875f-486d-ae77-6015671872de
< 5.0.3
MEDIUM 4.3 The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to authorization b… wordfence
66019297-a8a8-4bbc-99db-4b47066f3e50
< 1.2.1
MEDIUM 4.3 The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
65f521f4-1968-4c43-a3f0-b0f81632d7aa MEDIUM 4.3 The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and… wordfence
65f4978f-23c3-460d-958e-5aed66b071b4
< 1.0.0
MEDIUM 4.3 The Slick Google Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
← Prev 1484 1485 1486 1487 1488 1489 1490 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top