πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1526 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3cfd8b2d-cf2a-439d-9f9a-dbe499b1cd48
< 2.4.2
MEDIUM 4.3 The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access to functionality due… wordfence
3cec3799-cf44-412b-8590-b8fc60c58535
< 2.0.40
MEDIUM 4.3 Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress al… wordfence
3ce58796-98af-414c-a63e-3cf92ed293bd
< 5.2.40
MEDIUM 4.3 The B2BKing β€” Ultimate WooCommerce B2B and Wholesale Plugin β€” Wholesale Prices, Bulk Order Form & More plugin for Wo… wordfence
3cccfdcc-643c-4330-b345-aca4025e3327
< 2.1.4
MEDIUM 4.3 The Post Type Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
3cb8b08c-a028-48bd-acad-c00313fe06b8
< 3.1.14
MEDIUM 4.3 The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to … wordfence
3c973dd9-cfa3-4f06-a25a-c2786e3dca4d MEDIUM 4.3 The Bitcoin Donate Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
3c957f3f-fb98-49ff-b317-93b1accd0d47 MEDIUM 4.3 The WP Hide Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.… wordfence
3c9405f6-5e64-457d-9267-afbc9e159f36
< 2.1
MEDIUM 4.3 The wpShopGermany IT-RECHT KANZLEI plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
3c8602ed-6c0d-4357-93e6-bab1ab38ffb2
< 1.2.10
MEDIUM 4.3 The Donation Platform for WooCommerce: Fundraising & Donation Management plugin for WordPress is vulnerable to Cross-Sit… wordfence
3c7a192b-25cc-4041-a72b-34fbd697045b MEDIUM 4.3 The Bonanza – WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due … wordfence
3c63da0f-4be0-4716-8bde-4f2d4250f4af
< 1.1.11
MEDIUM 4.3 The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
3c4c8113-4c46-4179-9c7f-9d5d4337254d
< 3.2.3
MEDIUM 4.3 The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to una… wordfence
3c4b35f4-13e9-4406-85ce-6c8d4a13cd75
< 1.1.33
MEDIUM 4.3 The Semrush Content Toolkit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
3c434637-4bf9-46ee-9a6d-35eab7ef11a1
< 1.4.0
MEDIUM 4.3 The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
3c3ae044-1433-43b3-8185-03c194cefdbb MEDIUM 4.3 The Simple Nav Archives plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
3c25b462-cb9e-4250-bb17-9f2a0bd7665e MEDIUM 4.3 The NS IE Compatibility Fixer plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up… wordfence
3c1edb5f-905b-4364-9e1e-9035b951512c
< 2.2.2
MEDIUM 4.3 The EKC Tournament Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
3c1a7bda-29c5-4b4b-bbd8-71187609892e MEDIUM 4.3 The WordPress Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
3c0fb43c-f576-412e-a144-4725356ed9a0
< 3.6.3
MEDIUM 4.3 The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and includi… wordfence
3c088932-943b-4efc-88e6-0e93dc96eaf4
< 6.5.2
MEDIUM 4.3 The FileBird Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
3c07a2fe-97b1-45ec-bbd9-9353d679ed49
< 2.1.2
MEDIUM 4.3 The Mailrelay plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. … wordfence
3c065113-8481-4d84-9027-8eb0514ce61a
< 1.4.1
MEDIUM 4.3 The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
3bff5508-7483-4c0e-8146-a157244d6ad2
< 2.3.7
MEDIUM 4.3 The Testimonial Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… wordfence
3bfb9e92-dd4d-40fb-b339-ed0dbfc6b246
< 2.4.1
MEDIUM 4.3 The Mobile Contact Line plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
3bef108a-2c68-4347-bf53-559b2d877f6b
< 1.1.0
MEDIUM 4.3 The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a … wordfence
← Prev 1523 1524 1525 1526 1527 1528 1529 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top