πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1530 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
383da457-b930-470c-a68a-db3e87af7a80
< 2.9.1
MEDIUM 4.3 The White Label plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.0… wordfence
383a9771-1128-4993-bfb8-443ed26804fd MEDIUM 4.3 The Avada Custom Branding plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
3838bb64-fd85-43a4-97a2-7ca7930697ad
< 1.4.03
MEDIUM 4.3 The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
3837a55c-db77-4920-b2f6-c6a5a7faedf1
< 5.0.9
MEDIUM 4.3 The Dokan plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.8… wordfence
383309cc-d890-4ea6-9e77-5297fd631035
< 4.1.21
MEDIUM 4.3 The Eventin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.1… wordfence
38318605-40f7-4676-b409-f98a6c27cbfe
< 0.8.10
MEDIUM 4.3 The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, an… wordfence
3830c901-be36-4c4b-976b-d388b6af0c67
< 1.2.10
MEDIUM 4.3 The WooCommerce Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
38307432-399e-4887-867c-9eb2a0d90d70 MEDIUM 4.3 The Blog Manager Light plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
382a46c2-9fec-4642-93b0-c06b9ed1c086
< 1.4.6.1
MEDIUM 4.3 The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposu… wordfence
381ec109-ca51-4011-b7e0-aec636540d59
< 2.6.101
MEDIUM 4.3 The Smart Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on t… wordfence
38176c68-7932-4858-8cc6-b34128f55abe MEDIUM 4.3 The NewsExo theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.1. This … wordfence
38138775-2069-4878-ae41-06f53c74a0df
< 4.8.7
MEDIUM 4.3 The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Sensitive Information Expo… wordfence
37f6e19c-2e24-4a25-890f-60ebf7fdc2ae
< 5.2.7
MEDIUM 4.3 The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom… wordfence
37f0cb8f-80c7-457a-a92f-9cd6ad65c443
< 30.0.7
MEDIUM 4.3 The Contest Gallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
37eba0f3-d481-49a0-9f80-f42af55a71d2
< 1.1.3
MEDIUM 4.3 The Ovation Elements plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the … wordfence
37eb8847-0440-49c8-91cf-b23f6609ffce
< 1.8.0
MEDIUM 4.3 The Member Directory and Contact Form plugin for WordPress is vulnerable to unauthorized modification of data due to a m… wordfence
37d204b5-ffdb-4e0d-9f7b-2c2b70b1bab1
< 1.4.3
MEDIUM 4.3 The ACF Galerie 4 plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
37c5b868-37f6-44f1-8938-8a461cfa046b
< 2.5
MEDIUM 4.3 The Smart Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
37c31c26-c4fe-4c98-96de-6f4b0e3a36d4
< 1.2.6
MEDIUM 4.3 The Eight Day Week Print Workflow plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u… wordfence
37b5fcfd-654b-4151-9494-551799464c7c
< 3.3.2
MEDIUM 4.3 The Contextual Related Posts plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… wordfence
379dcd46-0a13-4c63-a655-c740f9bb460c
< 3.12.1
MEDIUM 4.3 The Custom 404 Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.… wordfence
379a7767-bb88-446f-806b-7a8e5c0584a6
< 4.3.3
MEDIUM 4.3 The Atarim plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
379547a2-6b22-4ec9-8570-a043dda7ec09
< 1.5.5
MEDIUM 4.3 The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized acc… wordfence
3772ddad-4960-48c8-904e-2457d12bd01c MEDIUM 4.3 The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-S… wordfence
3770f3d7-35ab-4f86-acc3-9d2816d50581
< 1.8.26
MEDIUM 4.3 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized access d… wordfence
← Prev 1527 1528 1529 1530 1531 1532 1533 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top