πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1497 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5cf62f45-a142-497e-9838-ce0b1b1bb3d3
< 2.9
MEDIUM 4.3 The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due… wordfence
5cefecf8-46dc-4ae1-9e94-b724beb7136f
< 2.20.0
MEDIUM 4.3 The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of da… wordfence
5cec2c52-d780-4d94-a5b2-d3b405bce49c
< 4.1.1
MEDIUM 4.3 The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to In… wordfence
5ceba1b2-2d39-4561-838b-b46e758517a3
< 3.7.32
MEDIUM 4.3 In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users w… wordfence
5ce729a2-a106-45ab-b96c-cfe75246def7 MEDIUM 4.3 The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, … wordfence
5cde239c-20bf-41fa-b7d6-e21b14dcbc22
< 9.7.12
MEDIUM 4.3 The Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic plugin for WordPress is vulnerable to una… wordfence
5cc00331-4c4d-44c9-9068-bd7320f9d4a5 MEDIUM 4.3 The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz… wordfence
5cb79fbc-705a-4fb4-b441-7fe7ab6dea10
< 1.51
MEDIUM 4.3 The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… wordfence
5cb00caf-6ca2-4970-8d09-14188806ba06
< 1.4.7
MEDIUM 4.3 The Wiki Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.6.… wordfence
5ca7b7c0-a94e-47ff-996d-4c7bbd62f0de
< 1.11.12
MEDIUM 4.3 The Easy Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
5ca55c87-6548-43b8-a23f-d31a51df9533
< 3.52
MEDIUM 4.3 The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
5c9d08f5-7c94-40e7-979f-023456aeb54e
< 5.9.1
MEDIUM 4.3 The Event Tickets and Registration plugin for WordPress is vulnerable to Information Exposure in all versions up to 5.8.… wordfence
5c92beb0-1fcf-4352-bd34-00e31b265c04
< 3.5.12
MEDIUM 4.3 The Slider – Ultimate Responsive Image Slider plugin for WordPress is vulnerable to unauthorized access of data due to… wordfence
5c8caf17-7844-4f26-b989-d29593b3ffda
< 2.3.2
MEDIUM 4.3 The Fluid Checkout for WooCommerce – Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
5c86269a-7d04-4a5a-9d0f-3dcc79fd7d25
< 1.2.1
MEDIUM 4.3 The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a… wordfence
5c852fa1-698b-4e72-b781-095e2a98df81 MEDIUM 4.3 The Clock In Portal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
5c7edfad-b45b-4297-876d-a063e02af0bf
< 3.2.4
MEDIUM 4.3 The Top 10 – Popular posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
5c6a9cfc-0b30-456e-bac5-4ad79cd08dce
< 1.2.2
MEDIUM 4.3 The Injection Guard plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check… wordfence
5c5d94dc-2ee0-4f04-99f0-8794e759c9e3
< 8.0.0
MEDIUM 4.3 The Element Pack Pro - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Cross-Sit… wordfence
5c2980c3-0038-42ab-8751-72c40921477a
< 1.1.8
MEDIUM 4.3 The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a… wordfence
5c1fd517-32ee-429d-9026-512afe117dc5
< 4.2.23
MEDIUM 4.3 The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized lo… wordfence
5c068079-0857-4116-8edb-1bc2fea3c6b7
< 2.6.3
MEDIUM 4.3 The WooLentor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.2. … wordfence
5bf209b8-7c12-4fc3-af7f-4fd25777caab MEDIUM 4.3 The WP Full Auto Tags Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
5bdba43c-0156-4a6b-b7b9-3f74b506e8f8
< 2.0.12
MEDIUM 4.3 The Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.… wordfence
5bd9ae0d-aa3a-4fb3-93b8-0e25bd01e162
< 4.1.1
MEDIUM 4.3 The Elementor Website Builder – more than just a page builder plugin for WordPress is vulnerable to unauthorized acces… wordfence
← Prev 1494 1495 1496 1497 1498 1499 1500 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top