πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1528 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3aade1bd-b69d-4134-a4f7-78372a291557
< 2.8.0
MEDIUM 4.3 The Download Manager and Payment Form WordPress Plugin – WP SmartPay plugin for WordPress is vulnerable to Insecure Di… wordfence
3aa6f3c2-0e45-4243-a26d-ba1c702fbe11
< 2.16.3.4
MEDIUM 4.3 The Knowledge Base documentation & wiki plugin – BasePress Docs plugin for WordPress is vulnerable to unauthorized mod… wordfence
3a9feacb-ef9c-40d4-abdb-a3fcfd529901
< 8.0.5
MEDIUM 4.3 The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option change… wordfence
3a923f58-f6c7-47ee-87f6-27453b39d1cf MEDIUM 4.3 The Mediabay plugin for WordPress is vulnerable to unauthorized use of functionality due to missing capability checks on… wordfence
3a89d81b-7d4b-4afc-8131-0acdc5298544
< 1.2.31
MEDIUM 4.3 The WP Time Slots Booking Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
3a845632-fcd3-4663-959d-d786667d0499
< 1.9.15
MEDIUM 4.3 The GPT3 AI Content Writer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
3a7f6fa5-ea69-4c58-994c-f9d3f3357a33
< 1.8.22
MEDIUM 4.3 The Bulk Edit Products for WooCommerce – WP Sheet Editor plugin for WordPress is vulnerable to unauthorized access due… wordfence
3a75a005-cf56-4841-a11b-318011d80fe6
< 3.4.5
MEDIUM 4.3 The WPKoi Templates for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
3a7440e2-637a-4f24-8452-e269e559aa17 MEDIUM 4.3 The Hyyan WooCommerce Polylang Integration plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
3a5a421a-3c76-4ea0-aa8a-878bbb7671d7
< 2.3.1
MEDIUM 4.3 The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
3a49f5f8-eec3-4b43-a007-329a7c1c6840
< 2.7.6
MEDIUM 4.3 The Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Part… wordfence
3a38c10f-b150-417a-8a00-df33edd9a08a MEDIUM 4.3 The Swiss Toolkit For WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
3a34e4ad-cdd6-4663-881a-d6e29cd86043
< 1.9.10
MEDIUM 4.3 The Envo Extra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
3a0d9356-8083-4154-aa04-9008627dd3f5
< 2.6.2
MEDIUM 4.3 The Sky Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,… wordfence
3a0b8c4d-44b4-4e94-a983-4feb73883386
< 4.7.0
MEDIUM 4.3 The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access d… wordfence
3a0a7a6d-7acd-4a70-b78d-da2ac697e374 MEDIUM 4.3 The Simple COD Fees for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
3a036855-35e0-4efd-aa27-16189b3538e9
< 6.7.56
MEDIUM 4.3 The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modif… wordfence
39e9f38c-f06e-4b6a-9f09-a23c52b50026 MEDIUM 4.3 The Smart Product Viewer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
39e35136-a096-40d5-8d6e-2667e7b83aaa MEDIUM 4.3 The Easy Appointments plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
39da62be-e630-48cd-b732-80ed3d337638
< 3.4.2
MEDIUM 4.3 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of da… wordfence
39ca4256-09c5-4f80-a04c-9429c8fe6b8b MEDIUM 4.3 The Slack Notifications by dorzki plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
39c9f055-2527-4678-bda1-27a29ab24acd
< 2.3.0
MEDIUM 4.3 The Products Quick View for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missi… wordfence
39c53cd7-3ea3-4971-be51-9544ca9d488f
< 1.3.5
MEDIUM 4.3 The Integrate Google Drive plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
39bb69e0-fb18-4737-9eb7-bda2b5bc16a2
< 4.24.8
MEDIUM 4.3 The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including… wordfence
39aed7e9-05c6-4251-b489-de7a33ed2c2e
< 4.6.5
MEDIUM 4.3 The YouTube Playlist Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
← Prev 1525 1526 1527 1528 1529 1530 1531 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top