πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1527 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3bdeb2a1-ab97-45ff-808e-37e631d5e9cf
< 1.2
MEDIUM 4.3 The Webcake – Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a mi… wordfence
3bdc076c-bc6d-442b-a1bb-9f3201153eb2
< 6.4.20
MEDIUM 4.3 The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to unauthori… wordfence
3bce6872-34d4-4675-bce9-e1197d801bce
< 1.3.0
MEDIUM 4.3 The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to… wordfence
3bce40ee-c378-4a44-9c5d-d83151975309
< 2.2.9
MEDIUM 4.3 The wpForo Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.… wordfence
3bc547f7-4f9e-4633-b881-107473dc980e MEDIUM 4.3 The Reviewer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
3bbc5e97-30a1-4774-a819-8a22a24436b6
< 4.7.16
MEDIUM 4.3 The MasterStudy LMS Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
3bb8e6c2-ca38-44a2-99d4-b3df62ed753c
< 1.3.1
MEDIUM 4.3 The Elegant Pink theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0… wordfence
3bb47765-f218-4864-8d0d-5880811e0514 MEDIUM 4.3 The Modalier for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
3ba1100e-8669-4105-b8d7-27c0b81c0856
< 6.8.9
MEDIUM 4.3 The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for Word… wordfence
3b955662-ce67-4c4c-8703-7460a7bcd4fc
< 8.3.14
MEDIUM 4.3 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
3b949792-7b04-4174-9b86-b2ad259017fa
< 10.3.4
MEDIUM 4.3 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized acces… wordfence
3b949389-65ca-4c95-ac84-46b5d7087c3d
< 5.1
MEDIUM 4.3 The Ads Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
3b7ce442-ad47-4b0d-8b30-b45cae4362ae
< 3.2.1
MEDIUM 4.3 The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
3b7aac1c-6962-49cf-850f-ab7b1d220090
< 1.2.91
MEDIUM 4.3 The WooCommerce PDF Invoice Builder for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce che… wordfence
3b7801b4-8d96-453e-b357-817972b3332b
< 2.0.9
MEDIUM 4.3 The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
3b52dab9-f518-4b66-ba2d-2e5b4aeb2bb3
< 4.2
MEDIUM 4.3 The Benchmark Email Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
3b5252ed-7901-4896-a574-46652d0dfc11
< 3.0.4
MEDIUM 4.3 The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPres… wordfence
3b4108b7-fa78-4f1f-9eee-0e2383b4988c
< 1.2.17
MEDIUM 4.3 The Ultimate Maps by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
3b34a0c6-3573-48c7-8edb-c9cf9503da06
< 1.2.14
MEDIUM 4.3 Various versions of a various YITH WooCommerce plugins that use the YIT Plugin Framework through 3.3.8 are vulnerable to… wordfence
3b007d8a-3096-42f3-a7be-e0e0d3addf0b
< 3.4
MEDIUM 4.3 Multiple plugins and/or themes for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is d… wordfence
3af9ece0-1556-4457-87ee-343daec5e74f
< 3.5.34
MEDIUM 4.3 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing c… wordfence
3af83ec2-9ebb-4cca-8523-8fe9b1517825
< 1.4.7
MEDIUM 4.3 The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in al… wordfence
3ae02595-17f0-472d-bc4f-6169cce7a583
< 3.5.2
MEDIUM 4.3 The Emailchef plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
3acaedff-f616-4b66-9208-f7e6a4df920d
< 5.0.10
MEDIUM 4.3 The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
3ab4e9c6-68b0-4113-bff0-c1d3c2d3dea4
< 2.9.12
MEDIUM 4.3 The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modificatio… wordfence
← Prev 1524 1525 1526 1527 1528 1529 1530 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top