πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1496 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5debe121-6373-4b56-8441-f0d4a5920089
< 1.0.5
MEDIUM 4.3 The Shortcodes for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu… wordfence
5de953ee-8a01-4372-a376-74a4cff674ce
< 3.7.1
MEDIUM 4.3 The DecaLog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.0. Th… wordfence
5de4f912-1dc2-48e8-a413-04b06a1b61f5
< 3.5.1
MEDIUM 4.3 The WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden plugin for Wor… wordfence
5de212c9-5c2e-4713-b1ce-022dd84520c3
< 3.9.4
MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollm… wordfence
5ddfea92-b790-4cf3-8b98-39c2374c7c31
< 1.0.4
MEDIUM 4.3 The ContentLock plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
5dd2f81c-8e7c-47e6-93ff-8d6ae2f23304
< 1.16
MEDIUM 4.3 The All in One Accessibility plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
5dd2a4cb-dd74-4b00-82f5-3bf1452e71a3 MEDIUM 4.3 The 10WebAnalytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
5dbbd1a0-de05-4510-b06b-8bc396b65a97
< 13.7.1
MEDIUM 4.3 The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
5db431b1-6601-490b-960f-4dda6c25c872 MEDIUM 4.3 The Hotlink2Watermark plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
5dae8e82-e252-48d9-ae1f-62acfcd17e2b MEDIUM 4.3 The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7… wordfence
5da8a4d4-9c98-4ee1-affd-105c88528c56
< 3.4.2
MEDIUM 4.3 The AI Engine (Pro) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
5d9e20f7-813c-4691-bce4-d0ff4774ae48
< 1.2.0
MEDIUM 4.3 The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for W… wordfence
5d96ea1b-1763-4a54-bd67-ac29175e9e01
< 1.20.27
MEDIUM 4.3 The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
5d716a6c-72b7-439f-8a99-56cd588515e3
< 3.4.5.1
MEDIUM 4.3 The Watu Quiz plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
5d6f38d7-a769-422d-ae3f-565cb1cc8a73
< 2026.2
MEDIUM 4.3 The Stop Spammers Classic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
5d572cac-b8e3-4c52-9b35-80fe5ee9e900
< 3.2.5
MEDIUM 4.3 The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improp… wordfence
5d3fa174-93c6-4086-b247-099d448a494f MEDIUM 4.3 The Elastic Email Subscribe Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
5d386d25-d228-4491-b58d-6adbb3b863a5 MEDIUM 4.3 The Vimeo plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.2. … wordfence
5d3251b8-4759-42c5-8fec-8b7f87e10b1a
< 20250820
MEDIUM 4.3 The Simple Statistics for Feeds plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
5d255ca7-37a5-4c1b-84be-356ae3900f7e
< 1.4.1
MEDIUM 4.3 The Block for Font Awesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
5d1ff79e-5246-422a-ae75-20763e7acd17
< 6.3.8
MEDIUM 4.3 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Informatio… wordfence
5d1dc9b4-9018-4e23-933b-5c03fa60d56a MEDIUM 4.3 The FastBook – Responsive Appointment Booking and Scheduling System plugin for WordPress is vulnerable to Cross-Site R… wordfence
5d1d012a-46cd-4c86-ac6f-993736a91acb
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
5d18f911-a766-4b13-a00e-8cdeee788d7a
< 2.3.0
MEDIUM 4.3 The Gutenverse Form – Contact Form Builder, Booking, Reservation, Subscribe for Block Editor plugin for WordPress is v… wordfence
5d01548e-91bf-44db-83dc-10c7d5962f9b
< 5.1
MEDIUM 4.3 The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… wordfence
← Prev 1493 1494 1495 1496 1497 1498 1499 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top