πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1506 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
52d6f0c3-2e2e-44cb-a5ea-85c19424ddac
< 4.2.6.9
MEDIUM 4.3 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
52d5b3d0-7871-4675-b11f-ba5924abd37b
< 2.9.1
MEDIUM 4.3 The The Aisle - Elegant Wedding WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missin… wordfence
52cdd3fe-9b53-4c7c-9538-e0c475d06ed3
< 3.8214
MEDIUM 4.3 The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
52b7b38a-6851-4c8d-8a53-08bf8934c089 MEDIUM 4.3 The Advanced Speed Increaser plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
52afc761-9050-4aea-97f6-62a9a2e1d65a
< 2.0.81
MEDIUM 4.3 The Easy Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
52ab644a-aed8-4690-8cea-a4993bf51ba0
< 5.3.2
MEDIUM 4.3 The Side Menu Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.… wordfence
52a8718f-2c4d-4da1-a81f-e93dff3fa43b
< 2.6
MEDIUM 4.3 The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin … wordfence
529f411a-8b3c-4cb9-b067-4755972d6c07
< 4.8.3
MEDIUM 4.3 The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
5292fcb2-4084-42e6-b78b-62e36123829a
< 1.4.4
MEDIUM 4.3 The Educare – Students & Result Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
52876909-3d2a-480d-9c47-39e96d088ff3 MEDIUM 4.3 The WP Tiles plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. T… wordfence
526dcd62-5e40-4870-b6cf-4f3d8bf9f8d0
< 5.2.7
MEDIUM 4.3 The Herd Effects – fake notifications and social proof plugin plugin for WordPress is vulnerable to Cross-Site Request… wordfence
52666087-3ecc-4901-8902-042179ae97fc
< 0.93.0
MEDIUM 4.3 The List category posts plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including,… wordfence
525923b5-4dda-4942-aaab-63d38cde31b6 MEDIUM 4.3 The Buttoner for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
5256ef2b-e1fc-4746-b35e-07a265f47f95
< 2.1.3
MEDIUM 4.3 The Events Addon for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
524ac3c0-d343-494f-8820-7a6bf290adbf
< 5.3.3
MEDIUM 4.3 The μ›Œλ“œν”„λ ˆμŠ€ 결제 μ‹¬ν”ŒνŽ˜μ΄ – 우컀머슀 결제 ν”ŒλŸ¬κ·ΈμΈ plugin for WordPress is vulnerable to Cross… wordfence
523c6436-6185-47cf-943e-d2f81c3f94b3
< 4.1.5
MEDIUM 4.3 The Booknetic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0 to 4.1.4. This is due to … wordfence
5238c344-d685-4eab-822c-d3c1050cc982
< 1.4.112
MEDIUM 4.3 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in… wordfence
523069b9-4449-416f-974d-40af842e5ebe
< 2.4
MEDIUM 4.3 The iNext Woo Pincode Checker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
5212567c-6134-4151-9fc6-eb4797ed0450
< 2.9.18
MEDIUM 4.3 The Gravitec.net – Web Push Notifications plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
5200ed9c-83dd-4f07-804c-2519932e5546
< 4.1.5
MEDIUM 4.3 Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. Af… wordfence
52001a06-e2e0-4d76-aa2d-0e9012357511 MEDIUM 4.3 The All-In-One Cufon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
520018db-d33b-4f2c-aaa5-611de792e11f
< 4.3.3
MEDIUM 4.3 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized email notification triggering… wordfence
51ff10f2-4a5b-42ab-9ee2-95b036ac1c9a
< 2.6.14
MEDIUM 4.3 The Mollie Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
51f94ce3-a11a-491e-b7d4-174cd17e2c8a MEDIUM 4.3 The Simple Travel Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
51f39839-0d9b-4b4e-883e-f2e9603bd8d2
< 1.2.2
MEDIUM 4.3 The SCSS WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
← Prev 1503 1504 1505 1506 1507 1508 1509 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top