πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1531 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
376c5091-7921-4470-acbf-44db53db38fc MEDIUM 4.3 The Appsero analytics tool used in several plugins is vulnerable to unauthorized modification of data due to a missing c… wordfence
376b46c9-f6bb-4f4e-8e53-62ca68d0003a
< 3.3.5
MEDIUM 4.3 The Rate my Post plugin for WordPress is vulnerable to Race Condition in versions up to, and including, 3.3.4. This can … wordfence
373c10df-0d9c-4f76-8d1f-cad6bcfed141
< 1.3.4
MEDIUM 4.3 The WP Content Pilot plugin for WordPress is vulnerable to Arbitrary Content Injection in versions up to, and including,… wordfence
37331768-c838-44e0-a22d-4bf4141dd820
< 3.6.21
MEDIUM 4.3 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Sensitiv… wordfence
37331460-4585-4946-9256-64fdb8f02a6b MEDIUM 4.3 The News Wall plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1… wordfence
3728c2bb-ff02-45b1-8bc8-112a68e3fabf MEDIUM 4.3 The URL Shortener | Conversion Tracking | AB Testing | WooCommerce plugin for WordPress is vulnerable to Cross-Site Re… wordfence
37276e9e-2b77-4259-b52f-f49da04f83e2
< 1.3.5
MEDIUM 4.3 The News Kit Elementor Addons plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
37264b0f-b021-41f8-a72d-3ee0d06b19a8
< 2.1.4
MEDIUM 4.3 The WP Insurance – WordPress Insurance Service Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery… wordfence
3710f139-0f17-426c-b48c-4c42ae4bab5f
< 8.6.1
MEDIUM 4.3 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an … wordfence
370ccbad-4001-4af5-8d32-fd6b04a8fc41
< 2.0.9
MEDIUM 4.3 The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient authori… wordfence
36f61f62-daa9-4b1a-91fb-7b22a28d0eda
< 1.0.4
MEDIUM 4.3 The ContentLock plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
36f41de5-50d5-47ca-bbd0-eca3b756a0cd MEDIUM 4.3 The Securimage-WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6… wordfence
36f3e9be-9a4e-458d-92b3-687afc44696a MEDIUM 4.3 The GS Insever Portfolio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
36eaff34-50cd-4399-8314-19ae4f50d017
< 1.0.31
MEDIUM 4.3 The Homerunner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
36e8a99e-47ae-4102-b056-624eca381161 MEDIUM 4.3 The Shiprocket plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi… wordfence
36e098fe-d1f9-4c8f-ae6b-222cbd5976b2
< 1.5.13
MEDIUM 4.3 The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
36dd9cbd-dac5-46a4-9593-1dce77ea731a MEDIUM 4.3 The TrustMate.io – WooCommerce integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
36cf102b-bff1-4516-9a76-030ddc98c207
< 7.6
MEDIUM 4.3 The ANAC XML Bandi di Gara plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
36cec19a-4631-4ada-b37a-f4b2dc264096
< 1.32
MEDIUM 4.3 The Simple Blog Card plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includi… wordfence
36c377cc-4169-4f9d-960f-518f7c4191d7 MEDIUM 4.3 The Grand Photography theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
36ba23ea-7e79-4048-8030-7ed6b2ff45a6
< 3.8.4
MEDIUM 4.3 The EmbedPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.3.… wordfence
36b51282-073a-4c75-a707-62e37cd878da
< 7.1.15
MEDIUM 4.3 The Theme My Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.… wordfence
36a43b08-872e-4760-a319-67e30fd004a2
< 1.6.0
MEDIUM 4.3 The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
36986585-7aaa-4c49-b426-fb9078fbb9ae
< 2.8.0
MEDIUM 4.3 The DirectoryPress Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
3698176e-1b0a-4864-a233-e920b6b326f0
< 1.3.1
MEDIUM 4.3 The Bulk Menu Edit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
← Prev 1528 1529 1530 1531 1532 1533 1534 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top