🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1489 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
64a8cfdb-0e81-451a-aa46-9b99be781079
< 2.9.33
MEDIUM 4.3 The Netgsm plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
64a36778-c17c-44ee-8b09-c221d27184f8
< 1.0.11
MEDIUM 4.3 The WP Dashboard Notes plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… wordfence
64902171-89da-44a1-b9df-bafdb27da7a6
< 7.8.0
MEDIUM 4.3 The SUMO Memberships for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… wordfence
648e70e7-1cb3-4e5d-ac7a-bc6340d39e09 MEDIUM 4.3 The Append Content plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
64852c99-f1f2-4f87-84bb-59e5b3655802
< 1.3.96
MEDIUM 4.3 The Appointment Booking Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
6480715e-efb7-4dd2-8938-c5b662d86461
< 4.16.17
MEDIUM 4.3 The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… wordfence
647be51d-e137-4e7c-a336-0a5023881c64
< 3.2.8.1
MEDIUM 4.3 The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
64792dd9-f16b-4929-a2ba-a6f53b2e975f
< 2.6.2
MEDIUM 4.3 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
64584fcd-be84-4d40-bfa8-e6131d0afd58
< 7.3.11
MEDIUM 4.3 The Quiz And Survey Master plugin for WordPress is vulnerable to authorization bypass due to a missing user validations … wordfence
64559d37-0c6b-45f5-8a2a-6e70cb5e423c MEDIUM 4.3 The WP Custom Widget area plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing ca… wordfence
64553742-ff2b-40e9-92c3-3458a9f988a2
< 3.0.12
MEDIUM 4.3 The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
6450dafd-5992-4831-87af-e5e47cc8663e
< 2.0.7
MEDIUM 4.3 The Edwiser Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,2.0… wordfence
644e2267-c90b-4517-8ded-f2b7c7ec3d27 MEDIUM 4.3 The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
64452bb0-32bc-4acf-8e89-f6ae7c75cef4
< 1.5.6
MEDIUM 4.3 The Ultimate Addons for Beaver Builder - Lite plugin for WordPress is vulnerable to authorization bypass due to a missin… wordfence
643ea2b3-246b-40a9-ba48-e10a7d6cdd11
< 1.1.0
MEDIUM 4.3 The WR Price List Manager For Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
642dc1d3-a008-4af8-ba9e-dbdd37b93126 MEDIUM 4.3 The Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time plugin for WordPress is vulnerable to … wordfence
64251fd4-1627-49d0-831f-5cb9898c38bf
< 1.5.0
MEDIUM 4.3 The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin… wordfence
6424de06-95ca-4148-9b24-0df0a2a8871d
< 1.17.0
MEDIUM 4.3 The SMTP2GO for WordPress – Email Made Easy plugin for WordPress is vulnerable to unauthorized access in all versions … wordfence
6424c34a-a4cd-49fc-a6d4-b2bbd9dcb42c
< 6.3.2
MEDIUM 4.3 The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access du… wordfence
64248d15-e6a7-442f-b269-e9f629d297d3
< 3.4.2
MEDIUM 4.3 The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
642012fa-28a5-46dc-a68f-3a4ce1cbced3
< 2.8.32
MEDIUM 4.3 Cross-site request forgery (CSRF) vulnerability in the Contact Form DB (aka CFDB and contact-form-7-to-database-extensio… wordfence
641f7727-83ba-45c2-b3e1-1ce19f86eac7
< 5.9.4.5
MEDIUM 4.3 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modificatio… wordfence
64117878-2fa3-4f80-bec4-f3f10b879f83
< 4.2.0
MEDIUM 4.3 The Church Admin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
640e24f6-2a0b-4435-a659-d034611d07e4 MEDIUM 4.3 The TM Replace Howdy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
640e109c-366f-4217-98e8-b1e5a0f0f062
< 4.0.0
MEDIUM 4.3 The WP Dummy Content Generator plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
← Prev 1486 1487 1488 1489 1490 1491 1492 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top