πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1491 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
630e4595-4be3-4886-8771-f781bcee674d
< 2.1.9
MEDIUM 4.3 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
63099a49-913f-428d-b9a4-85e1bc5afe56
< 6.0.7.7
MEDIUM 4.3 The RegistrationMagic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
630083ca-b667-4fde-b9be-14087eda721b MEDIUM 4.3 The Sertifier Certificate & Badge Maker plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
62f19301-2311-4989-a5f2-9f845b72dd54
< 1.8.3
MEDIUM 4.3 The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu… wordfence
62ea1427-0990-4645-aa1a-42da6fd3944f
< 4.2.2
MEDIUM 4.3 The miniorange otp verification plugin for WordPress is vulnerable to unauthorized admin notice dismissal due to a missi… wordfence
62e01d59-e649-4b84-993b-9faf28a24274
< 2.7.5
MEDIUM 4.3 The Simple History plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.7.4… wordfence
62d92e24-2f6f-435c-b468-6da0b5c3ae38 MEDIUM 4.3 The Reformer for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
62cc4e29-f87e-40e7-8ae0-14a7d3bff462
< 1.2.17
MEDIUM 4.3 The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… wordfence
62c58bd6-77c1-48a9-bfcb-e2bdd7f5e98e MEDIUM 4.3 The Worker for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
62c1b5ce-cd58-4805-9a40-1af529604406 MEDIUM 4.3 The About Me 3000 widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
62bc3794-a2c2-4c1a-b1c9-2be6e2526635
< 1.6.3
MEDIUM 4.3 The Zita Elementor Site Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… wordfence
62b7f07a-8289-4e06-b0f9-d0ae53d71a47 MEDIUM 4.3 The UpStream: a Project Management Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to… wordfence
62b58b5c-bd1e-4317-9300-461558c95ac2
< 2.0.0
MEDIUM 4.3 The 404 Image Redirection (Replace Broken Images) plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
62aa0cc4-ef8e-4727-ac07-3481c0464b05
< 4.7.8
MEDIUM 4.3 The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Insecure D… wordfence
62a79a8e-905c-4bed-b24d-84e56d7bb850
< 2.6.17
MEDIUM 4.3 The Five Star Restaurant Reservations plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
62a5c796-1c14-4cb1-9f21-340b40e418df
< 1.3.60
MEDIUM 4.3 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_… wordfence
629f36e3-f4a4-43a6-a98b-960088c8dd77 MEDIUM 4.3 The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
62998f65-5c99-490d-829f-4d63a9a20287
< 4.1.7
MEDIUM 4.3 The Church Admin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the seve… wordfence
629893b3-b5a9-44a1-89f0-a6ed35259b81
< 1.3.5
MEDIUM 4.3 The Address Autocomplete via Google for Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
62988723-4e58-4eb3-a483-127b23574a40
< 2.0.15
MEDIUM 4.3 The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make… wordfence
62805bc2-16e6-4252-bea1-5c2b69cf9bc8
< 1.01.4
MEDIUM 4.3 The Builder for WooCommerce reviews shortcodes – ReviewShort plugin for WordPress is vulnerable to Cross-Site Request … wordfence
627eb000-086e-408a-8123-063fed6364be
< 5.3.6
MEDIUM 4.3 The Order Splitter for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca… wordfence
627cb8f8-3684-48ab-953e-555f84cfb32d MEDIUM 4.3 The SP Project & Document Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and i… wordfence
6276a405-4879-4429-8fc1-2d567ded5112
< 5.9.4
MEDIUM 4.3 The Meta Box – WordPress Custom Fields Framework plugin for WordPress is vulnerable to information exposure in all ver… wordfence
625c1df5-6655-4319-8833-5519b464e53e
< 1.7.06
MEDIUM 4.3 The WP GPX Map plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
← Prev 1488 1489 1490 1491 1492 1493 1494 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top