πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1529 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
39ab0d8c-0f20-40d5-94ba-f6e95ebde88c
< 1.2.5
MEDIUM 4.3 The Easy Accordion Gutenberg Block plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
39a50c49-5c24-4ae7-8f77-4f3d98270f8f
< 1.0.6
MEDIUM 4.3 The Real Estate Directory theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
39893f56-aa92-4425-8ec4-979c72703e02 MEDIUM 4.3 The Add image to Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
397f9aa1-a40b-4aec-bd50-8fcfed590889 MEDIUM 4.3 The Bet sport Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
396f2426-7bc4-4221-bc48-920bec5af6e5
< 4.7.6
MEDIUM 4.3 The Phrase TMS Integration for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to … wordfence
3967b5ce-f0f8-4620-8883-0857aeee8f8b
< 1.0.10
MEDIUM 4.3 The HAPPY – Helpdesk Support Ticket System plugin for WordPress is vulnerable to authorization bypass due to a missing… wordfence
39560e9e-6583-43d0-9a02-2add8c30291a
< 1.3.21
MEDIUM 4.3 The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to… wordfence
39493083-e703-4893-b315-4e55df69276c
< 6.2.1
MEDIUM 4.3 The Simple Social Media Share Buttons – Social Sharing for Everyone plugin for WordPress is vulnerable to Cross-Site R… wordfence
3936dfb4-4f0f-4f97-bd66-df43dae93b5e
< 1.6.7
MEDIUM 4.3 The Zita Site Library for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
3931cfe6-13f7-4524-8895-d71918fd3ba3 MEDIUM 4.3 The Microblog Poster – Auto Publish on Social Media plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
38ec647a-3c0c-4d3c-ba34-64c17803867b
< 4.3.1
MEDIUM 4.3 The GetGenie plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.0. Thi… wordfence
38db911b-cad5-4c8c-b0a4-70dc543b4591
< 11.1.5
MEDIUM 4.3 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypa… wordfence
38d6c373-5752-48fb-900d-4adeaf575fe2 MEDIUM 4.3 The Product Carousel Slider for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
38b8b563-10a4-4343-b95a-7d09cf6fd729 MEDIUM 4.3 The Sosh Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
38adede2-73ca-470c-8ace-4f5bbec51d28
< 3.2.5
MEDIUM 4.3 The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… wordfence
38aa649c-e9d3-458b-b567-e2e751aaca00
< 2.4.5
MEDIUM 4.3 The Homey theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.… wordfence
38a90190-569f-46d8-bef4-fe28caf5e2fc
< 7.1.2
MEDIUM 4.3 The Booster Plus for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa… wordfence
38a5be0c-f905-4e27-b5c3-8c0606d71a61
< 1.35.14
MEDIUM 4.3 The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, … wordfence
3898ff24-3a9c-4aba-af76-2d2e99fd1693
< 2.1.20.1
MEDIUM 4.3 The JetWooBuilder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
388ce0d2-47d9-4c45-904c-ed7ef25b3416
< 2.1.0
MEDIUM 4.3 The FluentCommunity – Ultra-Fast High-Performance Social Network, Community, LMS & Online Courses plugin for WordPress… wordfence
3889aa6f-987a-4a2d-80fd-28628a6ed287 MEDIUM 4.3 The Sync Feedly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
387845f9-56ca-4581-bb3f-a933fbaa45c4
< 2.234
MEDIUM 4.3 The Ashe theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.233. This i… wordfence
386d907e-bc05-40d7-8a43-c807927e8a9a
< 5.8014
MEDIUM 4.3 The Ebook Store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5… wordfence
3861776a-be47-44e4-84b5-b3c31856e162
< 1.1
MEDIUM 4.3 The Build Private Store For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
38537f60-52f4-4007-b26f-6948b9263931
< 2.13.0
MEDIUM 4.3 The Putler Connector for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mi… wordfence
← Prev 1526 1527 1528 1529 1530 1531 1532 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top