πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1494 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6003b1bf-b176-4ca9-9de2-58133259e0f6
< 1.9.9
MEDIUM 4.3 The WP Docs plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.8. Th… wordfence
5fdce73f-b221-4c4e-a341-ce82d0fd8836
< 1.8.18.0
MEDIUM 4.3 The WP Mailster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
5fdbc9bc-70cf-4440-b12d-dd98844d33bc
< 2.4.33
MEDIUM 4.3 The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i… wordfence
5fdba3c5-382e-4d2b-83d8-0e0cebf2e63c
< 2.2.9
MEDIUM 4.3 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
5fcbdd9e-90c0-4883-9dac-07410b9c9a3f
< 8.0.12
MEDIUM 4.3 The Site Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… wordfence
5fbd1c5c-d23a-4f89-9225-514552d6ea70 MEDIUM 4.3 The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.3.… wordfence
5fbb41db-5369-465e-80a7-3490df46e07e
< 3.6.3
MEDIUM 4.3 The Sequential Order Numbers for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
5fb176f2-d966-4d78-9915-e6903d8f226a
< 1.8.38
MEDIUM 4.3 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
5fa88355-cb24-4dca-a730-08b185a6b9ea
< 1.1.9
MEDIUM 4.3 The Anant Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
5f91df7e-5d9d-4a3a-9afc-d771106a0be6
< 3.6.4
MEDIUM 4.3 The Kadence Blocks β€” Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization byp… wordfence
5f884516-85c8-4ef5-8d49-caa707433c4f MEDIUM 4.3 The Block Country plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0… wordfence
5f86dd96-fc87-4dc8-8435-f279a8def021
< 2.0.23
MEDIUM 4.3 The Blocksy theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.22. Th… wordfence
5f84f59a-6030-44e7-b51c-b51ef3631672
< 6.2.7
MEDIUM 4.3 The miniOrange 2FA plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
5f84140f-2572-4ffb-9b38-22eed5b0f80d
< 2.4.4
MEDIUM 4.3 The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
5f7b1e2d-e210-47f6-8dca-d7abb75edf35 MEDIUM 4.3 The Invelity MyGLS connect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
5f7a5d4b-8ba2-45d8-92d4-3c66a81fb4f8
< 2.0.2
MEDIUM 4.3 The Quotes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to missing capabi… wordfence
5f7660ba-c3be-44f0-91cb-809d0021759a
< 5.4.3
MEDIUM 4.3 The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorizati… wordfence
5f71c834-15ee-48ea-8f8d-6ea4b72a14d8 MEDIUM 4.3 The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, … wordfence
5f66ebef-b6ea-4f8c-a15d-11b15a77cb80
< 3.14.0
MEDIUM 4.3 The Seriously Simple Podcasting plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
5f4f07bf-192c-442f-ad68-fea1a84c5e87 MEDIUM 4.3 The Backup and Move plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
5f43e35e-55cd-45f1-b8a5-e47398d97cc2
< 5.3.8
MEDIUM 4.3 The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPre… wordfence
5f38f9f0-7c15-4c07-b501-b523ea58432a
< 5.9.8.5
MEDIUM 4.3 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in … wordfence
5f2c157b-cd5a-459d-8e26-859e686148dc
< 4.11
MEDIUM 4.3 The Ajax Search Lite plugin for WordPress is vulnerable to Missing Authorization (leading to Sensitive Information Discl… wordfence
5f29d895-ff0a-4ff9-9998-e7ab1a95d797
< 2.8.0
MEDIUM 4.3 The Awesome Event Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
5f1f3562-f869-4442-b77f-c06c5683c1b2
< 1.0.29.2
MEDIUM 4.3 The Website Monetization by MageNet plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
← Prev 1491 1492 1493 1494 1495 1496 1497 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top