πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1525 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3e270633-0031-41c1-98ac-ce96cd599a60
< 2.0.1
MEDIUM 4.3 The Mailchimp List Subscribe Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
3e16da38-709a-4b9a-9f00-efe8459a1318 MEDIUM 4.3 The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
3e0b4faf-35cd-4f59-ae77-fb4f4819ad32
< 6.8.4
MEDIUM 4.3 WordPress core is vulnerable to Missing Authorization in all versions up to and including 6.9.1. This is due to a missin… wordfence
3e011042-6d90-42e2-a967-b3e00a89be47 MEDIUM 4.3 The WP Ajax Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
3df9f237-a861-43fc-8623-d42f84d8d5d1
< 4.0
MEDIUM 4.3 The Locations plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.1. … wordfence
3df651ff-281a-4b39-9e24-f594ba987659 MEDIUM 4.3 The Browser Caching with .htaccess plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.2.1. Th… wordfence
3df11929-37be-4c52-ae53-fbbe926659b7
< 2.52
MEDIUM 4.3 The WP-Stats WordPress plugin before 2.52 does not have CSRF check in admin-menu when saving its settings, and did not e… wordfence
3deffe49-c40e-4231-b9d6-035f6dc5f8b2
< 11.3.56
MEDIUM 4.3 The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Informatio… wordfence
3deee9b5-2e36-447d-a492-e22e3dc6a5ab
< 6.5.3
MEDIUM 4.3 The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
3de1bcd7-24a8-4566-819b-d6653344e132
< 1.1.7
MEDIUM 4.3 The AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One plugin for WordPress is vulnerabl… wordfence
3dc69bba-39e0-46bd-8cdb-7cf1f7d36282
< 1.9.7
MEDIUM 4.3 The Accordion Slider plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability c… wordfence
3dc26eaa-2da5-4cd6-b613-4da2faad0f3b
< 2.21.3
MEDIUM 4.3 The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.21.2. Th… wordfence
3d97eee1-0f72-4dd3-998a-acb454fa5e8a
< 1.7
MEDIUM 4.3 The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… wordfence
3d9179d2-2e90-4de7-8178-073a0ce5865b
< 1.3.4.4
MEDIUM 4.3 The HUSKY – Products Filter for WooCommerce (formerly WOOF) plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
3d7e4d9c-d088-48db-88b7-09205115636f
< 5.2
MEDIUM 4.3 The Optimize Database after Deleting Revisions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… wordfence
3d7a544b-73a1-4883-a2d2-df42de08ff08
< 3.5.7
MEDIUM 4.3 The YayPricing plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
3d5ee8f1-8d86-4af0-af01-b31d2ff993d1
< 4.6.5
MEDIUM 4.3 The WP ULike plugin for WordPress is vulnerable to Race Condition in versions up to, and including, 4.6.4. This can lead… wordfence
3d5bc7a0-89b8-47fc-a6fa-7eb141d2be31 MEDIUM 4.3 The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
3d57d39f-f927-474f-a2e0-c9ac06e284d3
< 1.2.9
MEDIUM 4.3 The Simple Restrict plugin for WordPress is vulnerable to Information Exposure in all versions up to 1.2.9 (exclusive) v… wordfence
3d3516e7-cce4-4def-be38-d16be3110d59
< 1.3.88
MEDIUM 4.3 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
3d2f79ef-599f-48fc-b198-33c0407ad90d MEDIUM 4.3 The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0… wordfence
3d2d6d60-27a1-472b-b124-d1a5d5ddeaea
< 3.1
MEDIUM 4.3 The WP Popup Window Maker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
3d0efe1d-69ad-483c-b200-38873f88433b
< 1.3
MEDIUM 4.3 The Meks Smart Social Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
3d0d2398-4882-4f07-8259-af7a9b724526
< 2.5.6
MEDIUM 4.3 The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vuln… wordfence
3d01a40f-0af4-454c-9148-70804d571365
< 2.3.8
MEDIUM 4.3 The Kadence Blocks Pro plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, … wordfence
← Prev 1522 1523 1524 1525 1526 1527 1528 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top