πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1501 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
582e15cb-b924-4c24-818e-dfc2900f82c3
< 2.10.2
MEDIUM 4.3 The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to,… wordfence
5827a095-4cf9-409e-8bbd-b414982836b6
< 4.6.7
MEDIUM 4.3 The Video Conferencing with Zoom plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
5825deef-3bfa-4249-a3df-f05d00ef4a7e
< 5.0.11
MEDIUM 4.3 The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to unau… wordfence
5811fc63-da34-43cb-ae33-a34a8795bb72
< 8.58
MEDIUM 4.3 The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on… wordfence
5802226f-95f0-4c79-b434-0f74c1f47f1a
< 2.2.8
MEDIUM 4.3 The Maspik – Advanced Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
57f09da9-0d2c-45db-b3ed-19a7c9f5a001 MEDIUM 4.3 The URL Media Uploader plugin for WordPress is vulnerable to unauthorized safe file uploads due to a missing capability … wordfence
57ef2e79-08b7-4e2a-ae63-957d197e24ac MEDIUM 4.3 The Enjoy Social Feed plugin for WordPress website plugin for WordPress is vulnerable to unauthorized access and modific… wordfence
57e84624-98ab-495b-b985-908302527b3a
< 1.13
MEDIUM 4.3 The Soccer Engine – Soccer Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
57dbafe8-dcb3-4ac9-ad5e-76baf1963850 MEDIUM 4.3 The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
579b887a-4140-4e12-9a9a-ba52d212b8a2
< 6.1.5
MEDIUM 4.3 The Awesome Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6… wordfence
5798de72-b589-4474-82b2-df6ef26325a3
< 15.0.5
MEDIUM 4.3 The cformsII plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 15.0.4. … wordfence
5780d762-2313-4c81-be02-99543359d824
< 2.3.0
MEDIUM 4.3 The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization byp… wordfence
577a2783-244b-4449-a0f2-39d4be521acf
< 2.9.2
MEDIUM 4.3 The Campaign Monitor for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
57774f93-e6c0-46e6-8019-eab00b2b48ff
< 1.0.24
MEDIUM 4.3 The GoodBarber plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.23… wordfence
5776f689-56dd-413d-b02d-5551b97dd5eb
< 1.0.236
MEDIUM 4.3 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of d… wordfence
57734f6a-b592-4b01-b6a1-5636d48c0840
< 1.4.0
MEDIUM 4.3 The AffiliateX – Amazon Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
5770cb94-8603-44d9-8cda-925175851b51
< 2.0.2
MEDIUM 4.3 The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing c… wordfence
576ad141-e6c7-42f8-b069-936be24e57a0 MEDIUM 4.3 The WooCommerce Products without featured images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
575b51f4-fed4-4057-9e8b-762fda275ef3
< 1.9.2
MEDIUM 4.3 The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
575a648a-6bf0-42d9-964e-59800e856bd0
< 4.10.57
MEDIUM 4.3 The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
57580c2c-c3de-44a3-b586-f7092c06dc6b MEDIUM 4.3 The Chronosly Events Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
5754d2eb-dd31-4056-8a02-8b71b78f774b
< 1.6.3.1
MEDIUM 4.3 The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a m… wordfence
57465fce-e8ad-41ac-9dd6-e340ec314913
< 2.1.66
MEDIUM 4.3 The WooCommerce Products Vendor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to… wordfence
571fd575-ff03-465f-9e3c-574e93586396
< 2.7.6
MEDIUM 4.3 The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
571b391d-c839-43c3-bdf0-a9ad2222cb48
< 1.7.2
MEDIUM 4.3 The Metorik – Reports & Email Automation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forg… wordfence
← Prev 1498 1499 1500 1501 1502 1503 1504 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top