🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1524 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3efaf738-1ab8-4a22-9536-157c346e9536 MEDIUM 4.3 The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
3ef57441-8e35-44c4-b566-56e8f1dd18d9
< 4.10.0
MEDIUM 4.3 The Total Poll Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
3ee59570-85c3-4394-bebb-c3f49c08be67
< 1.07
MEDIUM 4.3 The Live News plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.06. T… wordfence
3eca4da3-2d8b-4a68-807b-d9a2cb52fb6b
< 2.9.9
MEDIUM 4.3 The پلاگین پرداخت دلخواه plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
3ec6f678-2538-483b-bb2c-90243b006721 MEDIUM 4.3 The MSN Partner Hub plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
3ec44487-7529-46a8-b2eb-cc5fe0f8f062
< 26.6.3
MEDIUM 4.3 The Betheme theme for WordPress is vulnerable to authorization bypass in versions up to, and including, 26.6.2. This is … wordfence
3ebfc9f5-abb7-47bc-bd38-f60df1cccb5d
< 3.8.1
MEDIUM 4.3 The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cros… wordfence
3ebe7680-a76d-4178-a729-f0d79d861912
< 1.8.3
MEDIUM 4.3 The NotificationX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8… wordfence
3ebaadf6-5085-4f2d-a377-34e318351449
< 2.1.5
MEDIUM 4.3 The Live CSS Preview plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
3ea8046a-b4cf-4122-b6f2-4945bc9c99ac MEDIUM 4.3 The Inquiry cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
3ea04257-a853-4501-9de7-5a4992c32ae9
< 4.1.1
MEDIUM 4.3 The Lazy Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on t… wordfence
3e8bf22a-a2bf-411a-89b6-ffd576b22c9f MEDIUM 4.3 The WP News Sliders plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
3e85ecd6-ed42-4875-9636-e2acbace5d83 MEDIUM 4.3 The sIFR plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.8.1. Thi… wordfence
3e7a63d2-fbe2-45e5-a042-ec8eb4edabdd MEDIUM 4.3 The Events, Calendars & Tickets – Event Kikfyre plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
3e78369e-976e-4086-bf82-ac7d3604e1c6
< 2.5.2
MEDIUM 4.3 The Admin Management Xtended plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
3e6fbf8b-5df5-4371-9bdf-fab1b242149f
< 14.2.5
MEDIUM 4.3 The Youtube Embed Plus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
3e6fb7b2-0d04-410f-84c7-55d20a29b6ab
< 0.0.10
MEDIUM 4.3 The Sigmize: A/B Testing, Session Recordings, Heatmaps & Revenue Tracking for WooCommerce, SureCart & EDD plugin for Wor… wordfence
3e5800fa-e0d7-435f-98c2-6d91df26d657
< 2.4.4
MEDIUM 4.3 The myCred WordPress plugin before 2.4.4 does not have authorisation and CSRF checks in its mycred-tools-import-export A… wordfence
3e557a3d-e520-42df-bbfa-26208e8964dd MEDIUM 4.3 The GoCache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
3e46a552-b0cc-4f46-a19e-1912244b5179 MEDIUM 4.3 The AI Responsive Gallery Album plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
3e44eeb0-c368-4490-9aa2-22c22046e2ec
< 2.1.6
MEDIUM 4.3 The Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution plugin for WordPress is v… wordfence
3e3dc509-73c3-4869-b520-6f5c1d691184 MEDIUM 4.3 The Simple Wp Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
3e34e774-30fe-49dc-b1f8-8dd63da65d23
< 1.6.1
MEDIUM 4.3 The WpTravelly plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.0.… wordfence
3e2a9d71-21ef-45a1-99ed-477066ce9620
< 1.4.1
MEDIUM 4.3 The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to sensitive information disclosure in… wordfence
3e27c0b0-c74f-47ad-b9ed-9fd6bd05d040
< 3.7.10
MEDIUM 4.3 The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to authorization bypass in all versions … wordfence
← Prev 1521 1522 1523 1524 1525 1526 1527 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top