πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1495 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5efd3125-8ba7-4d36-9e6c-cac101de7d5b
< 7.11.11
MEDIUM 4.3 The Avada theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.11.10. Thi… wordfence
5efbac99-561c-4abf-9e07-b5fdcfeb188b
< 1.14.5
MEDIUM 4.3 The DS Site Message plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
5eed65c6-f06e-49ee-a87c-5dcc442cb21f
< 1.7
MEDIUM 4.3 The HotelRunner Booking Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
5edaf310-c410-47dd-89cf-9aa15ab97acd
< 2.0.0
MEDIUM 4.3 The Gerencianet Oficial plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
5ec2743d-0d96-4056-8fdf-dc81d4e9b76f
< 3.5.5
MEDIUM 4.3 The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the lo… wordfence
5ebdf903-828e-4a22-953a-17d85984b576
< 2.5.9
MEDIUM 4.3 The AutomatorWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.8… wordfence
5eb85bc1-cffd-4363-ba53-30e3f6f6fc56
< 1.7.1
MEDIUM 4.3 The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when upda… wordfence
5ea02dd5-d837-471c-aa6a-264ffcedd55d
< 2.25.3
MEDIUM 4.3 The GiveWP for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.2. This is d… wordfence
5e934524-0294-4c43-a14d-817ef7d5bec6
< 1.2.5
MEDIUM 4.3 The Masterstudy Elementor Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
5e8311ea-5f38-4c15-be79-f1e913ac3d6e MEDIUM 4.3 The All push notification for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
5e75e877-14e6-4e51-b435-d78f8ab95d12
< 2.0.4
MEDIUM 4.3 Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote auth… wordfence
5e722b30-f136-4f57-a248-cf9cdd499552
< 5.1.1
MEDIUM 4.3 The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to unauthorized access due … wordfence
5e71bf15-aee0-4efc-a1c6-faad9f6e4f38 MEDIUM 4.3 The Crush.pics Image Optimizer - Image Compression and Optimization plugin for WordPress is vulnerable to unauthorized m… wordfence
5e6f4edf-c414-4a7c-a8d3-edee9f13d34b
< 1.3.6
MEDIUM 4.3 The Construction Landing Page theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
5e65bafd-471a-498a-a6ac-1bc87d25de67
< 1.2.7
MEDIUM 4.3 The GG Woo Feed for WooCommerce Shopping Feed on Google Facebook and Other Channels plugin for WordPress is vulnerable t… wordfence
5e57d859-cb71-47a7-9b5b-5a9360b8e2d1 MEDIUM 4.3 The Justicia - Lawyer WordPress Theme theme for WordPress is vulnerable to Insecure Direct Object Reference in all versi… wordfence
5e40af29-ecbc-48b0-a4ea-f263a4342a20
< 1.4.7
MEDIUM 4.3 The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is v… wordfence
5e3e9421-809c-423a-afcf-28c061c00fad
< 1.1.3
MEDIUM 4.3 The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1… wordfence
5e3de1a4-a534-475b-9138-2337755b0288
< 2.1.0
MEDIUM 4.3 The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi… wordfence
5e3dd131-dbd8-431c-96f4-4ab2c3be4dbd
< 3.1.14
MEDIUM 4.3 The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
5e31eda3-06f8-44c5-8b05-74283d4d20bb
< 4.6.4
MEDIUM 4.3 The Nexter Gutenberg Blocks – Website Builder & 1000+ Starter Templates plugin for WordPress is vulnerable to Sensitiv… wordfence
5e2e6775-219d-472c-8ebb-794bbff3e5ec
< 4.12.1
MEDIUM 4.3 The oik plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.12.0. This … wordfence
5e0b5709-70cd-482c-8ffe-3e40e3d35465
< 2.6.1
MEDIUM 4.3 The GDPR Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
5dfc145e-d2d4-4137-a5c6-dec2ebb41876
< 4.6.15
MEDIUM 4.3 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized modification of dat… wordfence
5def46b8-2b2b-4397-980e-76cb27ae42fe MEDIUM 4.3 The Delete Original Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
← Prev 1492 1493 1494 1495 1496 1497 1498 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top