πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1508 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
50959c4e-b7b9-45a1-9323-a1289ec1424f
< 3.1.4
MEDIUM 4.3 The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
507a4d4e-145c-47fb-a0b7-2344a749184e MEDIUM 4.3 The Free WP Mail SMTP (Official – 2019) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
50782dc3-1206-42ea-90c0-ab1b37b64e48 MEDIUM 4.3 The Userpro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check i… wordfence
5069fbc4-b3c4-4c0b-892c-2c83f35dc2fe
< 1.0.6.2
MEDIUM 4.3 The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is v… wordfence
5064d52b-0f3a-41f1-9e22-9ca5f9d6fb3a
< 2.5.8
MEDIUM 4.3 The Discussion Board plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
5064873b-e70a-4fe6-8c5c-ced6025aaa5f
< 1.6.6
MEDIUM 4.3 The AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPress is vulnerable to CSV … wordfence
504deb5a-cd51-4fad-8544-14b84f9f2ff9
< 4.0.7
MEDIUM 4.3 The Adminify plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
50499cd6-0e27-494a-892c-5ca827d4433b
< 1.5.3
MEDIUM 4.3 The Fatal Error Notify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… wordfence
503c00f5-59e5-4ca2-ac3d-a3f38a993f0d
< 5.2.6
MEDIUM 4.3 The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
503aafef-2496-46dd-9370-90a09f70a5d3
< 2.4.7.1
MEDIUM 4.3 The JetBlog plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
502bc68d-778a-47df-a5c2-6bd0b4f130cc
< 1.7.1.5
MEDIUM 4.3 The HTML5 Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
50212e01-4055-4e63-8cf2-6ee434f46604
< 1.5.4
MEDIUM 4.3 The Simple Revisions Delete plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
501be94e-c01a-43bd-b079-c11e60969def
< 2.6.1
MEDIUM 4.3 The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnera… wordfence
501a610a-7f11-4a03-b718-01c37cebe897
< 2.7.8
MEDIUM 4.3 The Serial Codes Generator and Validator with WooCommerce Support plugin for WordPress is vulnerable to Cross-Site Reque… wordfence
5018cc57-71e1-433c-94ab-da5c129f3071 MEDIUM 4.3 The WP Content Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
5007a9a9-faf6-493c-8adb-7260c8089bb2
< 3.6.11
MEDIUM 4.3 The Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers plugin for WordPress is vulnerable t… wordfence
5006f242-0dcc-462a-b8a4-b316d811dc0b MEDIUM 4.3 The WPSchoolPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
5004d789-6e59-403b-8df9-2030a976fc52
< 1.4.9
MEDIUM 4.3 The CM Email Registration Blacklist and Whitelist plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
50003b49-2c44-4f49-aaf9-8811bd4dda4f
< 1.9.18
MEDIUM 4.3 The Testimonials Showcase plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
4fee61cd-7359-4193-8cf2-86e0527a8ef1
< 4.9.50
MEDIUM 4.3 The WooCommerce Follow-Up Emails plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
4feacb75-0533-4f53-8ce9-3e45ee8336e2
< 1.14
MEDIUM 4.3 The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,… wordfence
4fe784a0-d466-4124-b712-18c19f9de53a
< 6.18.10
MEDIUM 4.3 The Website Builder by SeedProd β€” Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for W… wordfence
4fe1c440-f988-4020-9f80-77683ff652b2
< 4.1.2
MEDIUM 4.3 The OceanWP theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … wordfence
4fc3e24a-8b51-4b6f-bacf-665ceb03bc05
< 6.4.8
MEDIUM 4.3 The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for W… wordfence
4fa84388-3597-4a54-9ae8-d6e04afe9061
< 3.97
MEDIUM 4.3 The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
← Prev 1505 1506 1507 1508 1509 1510 1511 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top