πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1488 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
65b9fea3-323a-4123-ad83-3d713eb5552f MEDIUM 4.3 The Perelink Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.… wordfence
65b55b54-9af5-4f83-93f9-079cd51d8c91
< 2.7.11
MEDIUM 4.3 The Simple Local Avatars plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
65aedeef-d370-4d04-9396-1cf6a2b29033
< 1.32
MEDIUM 4.3 The WP Armour Extended plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
65ae71fc-cc3e-4208-99fe-ce1984515f5a
< 4.5.2
MEDIUM 4.3 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request… wordfence
65ad6138-d33b-4271-b059-c5f018af03c0
< 3.1.2
MEDIUM 4.3 The Advance Menu Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
65a3a9b7-b7ca-41f4-b808-7d955205a104 MEDIUM 4.3 The HTACCESS IP Blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
65a17f2e-8ce3-4d2e-8413-05826dcd9035 MEDIUM 4.3 The WP Database Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
65914bbf-6563-4bf2-a358-885e182a1365
< 3.4.2
MEDIUM 4.3 The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Br… wordfence
658ba848-fbfe-4cee-b997-77bc4cae53dc
< 2.4.0
MEDIUM 4.3 The Disable WordPress Update Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
65849267-8bb5-48fd-b95e-e89a1e744fe0
< 3.4.3
MEDIUM 4.3 The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a miss… wordfence
657bea00-9709-48b8-807a-c9a18b0aee1d
< 1.8.11.2
MEDIUM 4.3 The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is… wordfence
6560ba0b-2190-4d30-b0c4-f07d524ccfde
< 1.2.14
MEDIUM 4.3 The Premmerce Brands for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mi… wordfence
655fc91d-5920-4214-8ef1-8191e2683f9d
< 4.7.2
MEDIUM 4.3 The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
65581fa6-110f-4ae3-a903-dbf649b44417 MEDIUM 4.3 The ClickFunnels plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.… wordfence
654727e0-6129-47c7-94f3-10567b1a42d4
< 1.3.3
MEDIUM 4.3 The SendPulse Free Web Push plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
65301dc9-8c6c-44db-935e-9c719984bb1e
< 1.5.2
MEDIUM 4.3 The Travelfic Toolkit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
6525195e-5d90-4dd4-b9ee-612a8295c262
< 5.15.0
MEDIUM 4.3 The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference … wordfence
652367a0-fca2-4313-8217-d8811ada0ab5
< 1.2.102
MEDIUM 4.3 The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
6518a71b-1dd0-4bb5-b768-16674fc83120 MEDIUM 4.3 The Google Plus Share and +1 Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
6504ae5c-a36d-495e-aa93-40a3753857c6
< 1.4.5
MEDIUM 4.3 The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forger… wordfence
64f4789e-bbe7-4c07-86c6-f2767d6e1901
< 2.1.3
MEDIUM 4.3 The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up … wordfence
64e0adbc-c524-4f9d-9741-ce69edf888f7 MEDIUM 4.3 The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
64df8260-603b-48ba-b88b-f89994dd8329
< 1.3.2
MEDIUM 4.3 The WholesaleX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
64bd14de-a201-4532-b980-962feab0d69b
< 3.8.6
MEDIUM 4.3 The Polylang plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, … wordfence
64aadd20-a831-4550-b68d-827722a35c0f MEDIUM 4.3 The Optimize More! – CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
← Prev 1485 1486 1487 1488 1489 1490 1491 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top