πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1498 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5ba0ecd6-de5a-441c-a4f6-cdfa0ae0edee MEDIUM 4.3 The HidePost plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.… wordfence
5b9919d4-a947-4494-a316-5e2655a4a16f
< 3.3.1
MEDIUM 4.3 The Conditional Payments for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
5b962739-8308-4cbd-b14b-1aae440a677b MEDIUM 4.3 The Responsive Flipbooks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
5b82994c-c0bd-4e44-95a7-7480ffbb1aad
< 3.19.10
MEDIUM 4.3 The 12 Step Meeting List plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
5b823a9d-40b2-4308-b732-4a02a06e03e9
< 6.2.3
MEDIUM 4.3 The Hotel Booking Lite plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inc… wordfence
5b6349c5-a5da-4b8b-b60a-c1176a06e645
< 6.8.1
MEDIUM 4.3 The Coupon Affiliates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
5b62219a-c054-4ae6-ad00-b411995c2b9a
< 1.4
MEDIUM 4.3 The WP Podcasts Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
5b559a48-3c8b-4f8a-9627-c4f838d20af3
< 3.4.4
MEDIUM 4.3 The Interactive World Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
5b4e8413-2df6-432c-89b4-d675206e2afb
< 1.0.4
MEDIUM 4.3 The WeDesignTech Ultimate Booking Addon plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
5b39933a-d38e-421b-9fe4-70350e2f3da8
< 1.0.1
MEDIUM 4.3 The Instant Breaking News plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
5b315119-8fd8-4709-8907-b584877c0cfe MEDIUM 4.3 The Admin debug wordpress – enable debug plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
5b2c6eb3-6042-402d-88e1-8d9fc2291a81 MEDIUM 4.3 The Page Manager for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
5b1e6e52-6d4f-4901-859d-05cdec9beb52
< 1.12.11
MEDIUM 4.3 The BERTHA AI. Your AI co-pilot for WordPress and Chrome plugin for WordPress is vulnerable to unauthorized access due t… wordfence
5b127a47-d22f-47b5-92a8-440a5892a181
< 2.3.8
MEDIUM 4.3 The HT Politic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.7.… wordfence
5b09bfff-4d6e-4de0-b6ab-6ac27c4f2be6
< 1.8.7
MEDIUM 4.3 The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
5af799a4-0aee-4601-943e-82cbc860ede5
< 3.1.2
MEDIUM 4.3 The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
5af1063c-615e-4196-9fa6-960c008544c4
< 4.2.5
MEDIUM 4.3 The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to una… wordfence
5aef5113-6b80-4fe8-ac98-59c1a10a146f
< 2.6.0
MEDIUM 4.3 The Buddyboss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and… wordfence
5ae4d19a-26f1-491e-b0ac-0bb2c6cdd318 MEDIUM 4.3 The Create Posts & Terms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
5ae2d931-e188-4ab1-8e15-47fdee09e997 MEDIUM 4.3 The Contact Form Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
5ae08e0b-ea17-46c1-aad3-4ecea69c1bdc
< 1.1.2502030
MEDIUM 4.3 The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing cap… wordfence
5ac7408d-8ec7-415b-bf52-024182888cb4
< 2.4.6
MEDIUM 4.3 The W4 Post List plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, … wordfence
5abc627d-2d8e-44e6-8e8e-ad9f55cbb0d8
< 5.0
MEDIUM 4.3 The WP Bing Map Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 4.1.4. This is du… wordfence
5abc282d-68c9-423c-a15c-d4d3f7035661
< 4.3.1
MEDIUM 4.3 The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to un… wordfence
5abc0853-5888-4538-a6f3-78acef88ff63
< 1.23.00
MEDIUM 4.3 The E2Pdf – Export To Pdf Tool for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missin… wordfence
← Prev 1495 1496 1497 1498 1499 1500 1501 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top