πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1502 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
570e72de-1f6a-4bbe-9df1-f0d1ca290a0b
< 1.7.0
MEDIUM 4.3 The Currency per Product for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
570a9fc7-ad0d-4aa3-8c31-4d2f534cdbae
< 3.0.5
MEDIUM 4.3 The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
56fe9c56-db60-4af5-b206-6afe5be970cf MEDIUM 4.3 The SearchAzon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4. T… wordfence
56f44550-da65-4733-b4a2-a6db069db866 MEDIUM 4.3 The re.place plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.… wordfence
56f146e8-ec70-45c4-9ff2-94cb44fef5c2
< 1.23.00
MEDIUM 4.3 The e2pdf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.20.27. Th… wordfence
56d882a6-91eb-49bc-ae4d-86f3ea4b8813 MEDIUM 4.3 The IceStats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.… wordfence
56bbf263-149b-4419-9745-39dc147026a6
< 7.5.31.7212
MEDIUM 4.3 The FV Flowplayer Video Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
56b4b819-55d9-4523-96ef-e2a4ac7ecec9
< 4.2.12
MEDIUM 4.3 The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to unauthorized acce… wordfence
56a90042-a6c0-4487-811b-ced23c97f9f4
< 1.1.3
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability ch… wordfence
56a68cad-2abf-4b22-ae05-243e8901a9d8
< 1.0.13
MEDIUM 4.3 The Premmerce Redirect Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
56a2084c-5120-4115-a027-625900d23ebc
< 2.2
MEDIUM 4.3 The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
569b5522-8f38-454b-a8b5-12e3959c3348
< 4.4.10
MEDIUM 4.3 The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
56976e5f-13e9-45e3-8cd1-7ac5f34f4248 MEDIUM 4.3 The For the visually impaired plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
56963053-211a-43a4-ba2b-2f4d18416435
< 3.4.6
MEDIUM 4.3 The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
5689bd2b-1518-4b3b-81a3-cc92575f6c1f MEDIUM 4.3 The MMA Call Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
56887118-33e2-4eef-9364-930ca81bd59f MEDIUM 4.3 The eDS Responsive Menu plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
568545a4-7f73-4050-9724-d47279c340c9
< 3.2.21
MEDIUM 4.3 The Starter Templates β€” Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Cross-Si… wordfence
567fc4d3-622a-4b6a-b17a-3de91798b590 MEDIUM 4.3 The bellevuex theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
5678794d-244f-45d1-9049-fea01ba45989 MEDIUM 4.3 The Oceanic theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.53. Th… wordfence
5671d318-ca8c-4882-a522-f327e65a24f0
< 2.5.19
MEDIUM 4.3 The Most And Least Read Posts Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
565d3b4c-d810-41d5-b1ac-ec3363bcd6f3
< 6.8.0
MEDIUM 4.3 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulne… wordfence
56583dca-bd63-466d-a16a-be7b19b2487e
< 3.4.2
MEDIUM 4.3 The Houzez theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in a… wordfence
5653a87e-bcbb-4516-b936-7e659a396a56
< 1.2.4
MEDIUM 4.3 The Dark Mode for WP Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
564ec4a6-20d3-4b46-8637-fc1de586e19a
< 4.3.6
MEDIUM 4.3 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to payment… wordfence
562fe11f-36a0-4f23-9eed-50ada7ab2961 MEDIUM 4.3 The Easy Registration Forms for WordPress is vulnerable to Information Disclosure via the 'erforms_user_meta' shortcode … wordfence
← Prev 1499 1500 1501 1502 1503 1504 1505 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top