πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1500 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
597fe53e-769e-4edd-b0b9-2bd2cff50da6 MEDIUM 4.3 The Video Contest WordPress Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
597d6d6b-80d5-45d8-b013-2804fce12c85 MEDIUM 4.3 The spam-byebye plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
5974443a-48aa-4d5e-958a-40b99f68a1ae
< 1.2.0
MEDIUM 4.3 The Vandana Lite theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
5973afaa-5a64-4db1-8e32-3b39d1367eb8 MEDIUM 4.3 The SIS Handball plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… wordfence
5971447d-0634-49a5-91d0-c4f0c0825a86
< 4.0
MEDIUM 4.3 The Staff Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
595d0401-55b9-418e-8b99-48b23e9a2662 MEDIUM 4.3 The Rucy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.4.4. This … wordfence
595a6ab3-0731-4ef4-a385-5dfebbd917f4
< 4.25.3
MEDIUM 4.3 The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
59592b27-d431-499a-b3c3-3d43a5513c36
< 6.5.2
MEDIUM 4.3 The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorizat… wordfence
5954c35a-7d0a-4bc5-9cad-3223e7be56eb
< 0.1.0.9
MEDIUM 4.3 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
592d42eb-4025-44af-a519-672656ad8b0e
< 5.2.7
MEDIUM 4.3 The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation … wordfence
58f048e5-f4be-4452-8fed-16871f4020b6 MEDIUM 4.3 The WPDash Notes plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on … wordfence
58d25eeb-b12c-4850-8308-eaa30982b5a8
< 1.1.4
MEDIUM 4.3 The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du… wordfence
58cfb328-40d0-4bea-a707-d5d6c1ce364a MEDIUM 4.3 The Sticky Social Media Icons plugin for WordPress is vulnerable to unauthorized settings update due to a missing capabi… wordfence
58c35a21-1416-4926-a4ea-9c4fa3363114
< 2.9.2
MEDIUM 4.3 The Page View Count plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
58b48d86-9b88-468b-878d-1fabd3c3d778
< 0.5.4
MEDIUM 4.3 The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable… wordfence
58b29729-e9c3-4d57-affd-6142dfa8cc6f
< 1.0.7.5
MEDIUM 4.3 The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
5890360b-e0ef-4ec2-8117-1b4004573e93 MEDIUM 4.3 The Popup for CF7 with Sweet Alert plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
58898db3-e3fb-4903-8121-3a438a09122a MEDIUM 4.3 The Di Themes Demo Site Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
5881a375-39a1-4911-812e-1f968ad427f9
< 2.2.7
MEDIUM 4.3 The WP Docs plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
58804f7a-51af-4199-85c9-b75b91b5c59b
< 2.9.72
MEDIUM 4.3 The Netgsm plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
587b53aa-2369-4433-b0f1-7f054f5a0653
< 2.7
MEDIUM 4.3 The Pays – WooCommerce Payment Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
58756479-72f0-4c5e-8ed5-dfdbffed6026
< 4.6.6.1
MEDIUM 4.3 The MobiLoud – WordPress Mobile Apps – Convert your WordPress Website to Native Mobile Apps plugin for WordPress is … wordfence
585a9eb4-f394-4cb2-9050-659171a994d9
< 6.1.2
MEDIUM 4.3 The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1… wordfence
5849a9f6-715e-4ac8-a0f7-1cd0814fff58
< 3.9.5
MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refe… wordfence
58386353-93f5-4b87-8c72-c1b1341b884c MEDIUM 4.3 The Simple Google Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
← Prev 1497 1498 1499 1500 1501 1502 1503 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top