ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1493 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
60f7df44-22f9-4a9e-a20c-4b8628674079
< 10.14.15
MEDIUM 4.3 The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i… wordfence
60eda41d-7590-4e08-ba6b-6ae3505cfd34
< 4.8.56
MEDIUM 4.3 The Sharespine Woocommerce Connector plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… wordfence
60ed7738-5cba-4fc0-9178-265773555369
< 6.5.0
MEDIUM 4.3 The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modif… wordfence
60e0fd59-a69c-4ddf-80cd-4312d2689397
< 1.4.19
MEDIUM 4.3 The eRoom – Zoom Meetings & Webinars plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi… wordfence
60d65c7e-5533-4ac0-b2f0-339342224581
< 5.0.5
MEDIUM 4.3 The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missin… wordfence
60c6c9a8-e04d-49e2-96e8-16d7580a3e2c
< 6.15.21
MEDIUM 4.3 The Coming Soon Page, Under Construction & Maintenance Mode by SeedProd plugin for WordPress is vulnerable to Cross-Site… wordfence
60c63be2-dd17-4224-ba96-ba30ed0b25ce
< 3.5.0
MEDIUM 4.3 The DoFollow Case by Case plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
60c57b6c-4dc1-4fa6-bf14-7c5c74c704db
< 2.16.2
MEDIUM 4.3 The ЮKassa Ð´Ð»Ñ WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, a… wordfence
60bfe2cd-13a7-4739-a7d5-5ce7ed0d9ca8
< 2.3.2
MEDIUM 4.3 The Table Block by RioVizual – Comparison Table, Pricing Table, and Pros & Cons Box for Gutenberg plugin for WordPress… wordfence
60b05809-c70d-4670-9d49-d56164961074 MEDIUM 4.3 The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions… wordfence
60ab0311-888c-46ae-98fe-9e7d4dfe13bf
< 3.3.1
MEDIUM 4.3 The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga… wordfence
60864891-3a26-47da-a3e6-131fed607916 MEDIUM 4.3 The Booknetic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.9. … wordfence
60782340-8913-4114-8544-109337795f45
< 5.0.7
MEDIUM 4.3 The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to u… wordfence
60693832-ff40-4173-95d9-822630e3403e
< 1.4.107
MEDIUM 4.3 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access due… wordfence
60656c97-02ce-4783-bd7d-8be842db3b99 MEDIUM 4.3 The Couponer for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
605fbfb9-85d8-43ff-a738-ad1a8a9584c3 MEDIUM 4.3 The Bulk Resize Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
605fac87-e1e8-4354-a9d3-4440e54bc161
< 0.7
MEDIUM 4.3 The Duplica – Duplicate Posts, Pages, Custom Posts or Users plugin for WordPress is vulnerable to unauthorized modific… wordfence
6058da9e-8ca3-4966-bb10-e5da526e8c7e
< 1.3.5
MEDIUM 4.3 The Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.4. This… wordfence
604862d9-e032-4806-8a14-3e4ad0ae1ee2
< 2.5.32
MEDIUM 4.3 The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to Sensitive Information… wordfence
60413b3b-f9b0-40ca-af0a-f7cf87ab793a MEDIUM 4.3 The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
603b6c52-48eb-4e8c-a2c1-77b12a2b1a2c
< 1.0.117
MEDIUM 4.3 The Royal Elementor Kit theme for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing ca… wordfence
602d337e-0778-4182-8e77-0eb3b37d5a7a
< 1.2.2
MEDIUM 4.3 The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
602b24b1-d450-4d30-8030-120420882ea0 MEDIUM 4.3 The Radius Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference … wordfence
601ac722-a2d4-4dce-9cde-dd3f4c15416a
< 3.9.14
MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refe… wordfence
6013f592-4cff-4b94-968d-6f66e84368d0 MEDIUM 4.3 The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forg… wordfence
← Prev 1490 1491 1492 1493 1494 1495 1496 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top