πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1503 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
56161d67-7378-4349-8fe5-da73da36afa0
< 1.3.3
MEDIUM 4.3 The Featured Image Generator plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability… wordfence
560b0c48-c509-4000-b187-9d5dbdb2299d
< 2.0.5
MEDIUM 4.3 The f4 Post Tree plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 2.0.4. This… wordfence
5607cc07-5104-45d0-8279-ba0ef3ebcbe9 MEDIUM 4.3 The IRivYou plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.1. Th… wordfence
55f7e39b-e7a5-462b-b1e4-c3d92038f17e
< 1.3.60
MEDIUM 4.3 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_requir… wordfence
55f6ad7b-279c-40b7-aae7-15c2b61042f4
< 2.4.7
MEDIUM 4.3 The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress … wordfence
55f25d72-c0aa-4dbf-bb3f-ba010f7f7e69
< 2.9.7.4
MEDIUM 4.3 The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program. plugin for WordPress is vu… wordfence
55e6a968-153e-4d4c-a7be-65650a0c9bc1
< 2.7.1
MEDIUM 4.3 The Add Expires Headers & Optimized Minify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
55dfd822-9034-4982-bfe7-eb86119e1f07 MEDIUM 4.3 The WP Word Count plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
55db7d81-7ffb-49da-b64e-23e892bddc57
< 1.3.60
MEDIUM 4.3 The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
55d07502-ad2d-493d-acff-968d15c2810d MEDIUM 4.3 The Audier For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
55cfb2c6-ca3f-45b7-8cd9-a5a1c3783ae0 MEDIUM 4.3 The Responsive Accordion Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… wordfence
55c9bc15-0e1a-450a-a6cd-8459ea37ffff
< 6.3.7
MEDIUM 4.3 The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to unauthorized access due to a missin… wordfence
55c568b1-4f9e-4a1f-bad1-0a373c9d33ae
< 1.0.3
MEDIUM 4.3 The Demo Awesome plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the call… wordfence
55bb3620-c182-46c4-bc22-8526cf410cdb
< 1.5.89
MEDIUM 4.3 The KB Support plugin for WordPress is vulnerable to user data retrieval in versions up to, and including, 1.5.88. This … wordfence
55a70835-55cc-4056-b584-e1b56ba83f91
< 3.7.4
MEDIUM 4.3 The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
558b4b31-fd4f-4265-bddc-baf484d48fc5
< 1.3.9
MEDIUM 4.3 The WP Reactions Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
55895508-d0ef-4855-8d15-b8a45ba0dcb2
< 10.3.2
MEDIUM 4.3 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss … wordfence
55750dcf-c6ec-4be6-967f-60bf940fa30e
< 2.4.1
MEDIUM 4.3 The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to … wordfence
556e54d4-9e3a-4d9a-9e6e-0021f119c98b
< 1.2.8
MEDIUM 4.3 The WP Free SSL – Free SSL Certificate for WordPress and force HTTPS plugin for WordPress is vulnerable to unauthorize… wordfence
555f9bf9-5b76-4cbe-852b-5fffb1fc1b35
< 1.1.4
MEDIUM 4.3 The Virusdie – One-click website security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
555a69e2-7ff2-48ea-a4de-04d8a47d02e3
< 2.8.11
MEDIUM 4.3 The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t… wordfence
553f2cd8-9868-4190-91ea-88e03b9ddc3d MEDIUM 4.3 The WPBookit Pro - Appointment Booking Plugin for WordPress plugin for WordPress is vulnerable to Privilege Escalation i… wordfence
551272a2-6c2b-45b8-b2e5-330396c5680a
< 5.9.9.8
MEDIUM 4.3 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object R… wordfence
5511c5f4-b71c-484b-ab6f-2389a29809cd
< 1.8.13
MEDIUM 4.3 The GPT3 AI Content Writer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
54f6e6b4-ecf6-485b-a4f7-5878b8cace50
< 1.3.5
MEDIUM 4.3 The Benevolent theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.4. … wordfence
← Prev 1500 1501 1502 1503 1504 1505 1506 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top