πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1532 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
368c2c5d-0618-4c32-ad43-71fd742126d0
< 1.0.12
MEDIUM 4.3 The Ultra Addons for WPForms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
368bf2b9-3c9e-4da9-8651-bef856981604 MEDIUM 4.3 The xSmart theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
3681a51f-89a3-4d6a-a292-25e3f0c4b546
< 45.16.0
MEDIUM 4.3 The Visual Composer Website Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
3670665c-0ae1-47d6-b463-581eb195666e
< 3.23.4
MEDIUM 4.3 The My YouTube Channel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
365f29d5-600e-42f9-b561-8d9b93dbfd87 MEDIUM 4.3 The Ultimate Auction plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
364b3501-3cfd-4ef1-b3ed-34428174b30d MEDIUM 4.3 The Sticky Header On Scroll plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
3636e6e0-292c-44c6-b2cb-5a333e910b7a MEDIUM 4.3 The JobCareer theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a… wordfence
3624f8d7-1dcd-46df-8d9f-b51bb09719f2 MEDIUM 4.3 The Blackfyre theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.4. T… wordfence
3623713f-ad39-429c-890f-cd113efb905a MEDIUM 4.3 The The integration of the AMO.CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
36231136-58ec-4a6d-8cfc-d3d69c31037d MEDIUM 4.3 The FunKItools plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
3613c0ce-ac77-4fdc-8e3a-830b45ef6390 MEDIUM 4.3 The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to unauthorized… wordfence
36129b06-b91d-4468-8566-1be0fb1d34b4
< 2.2.3
MEDIUM 4.3 The WP Hotel Booking plugin for WordPress is vulnerable to rating manipulation in all versions up to, and including, 2.2… wordfence
361216af-b939-4ac1-ae06-97552d283670
< 1.1.3
MEDIUM 4.3 The Leadster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. T… wordfence
35fd77f2-321c-4194-b7e0-7fdd50b50047
< 3.5.23
MEDIUM 4.3 The Easy Property Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
35f82406-f75d-4510-81c0-14af3d944bf0
< 4.0.12
MEDIUM 4.3 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a… wordfence
35f78106-e75d-4d60-b37a-5d097da9413b MEDIUM 4.3 The WP Twitter Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
35ec9787-81f2-46c9-98d7-29095181a531
< 3.1.2
MEDIUM 4.3 The wpForo Forum plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu… wordfence
35d9105d-0b1f-494b-a05c-2b0571599084
< 7.27
MEDIUM 4.3 The W3SPEEDSTER plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.25.… wordfence
35cd1788-1756-4d03-8f6f-e5e4153e3f4f
< 1.0.21
MEDIUM 4.3 The CP Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.20.… wordfence
35c7901a-49da-4df4-a9b2-966326b1310d MEDIUM 4.3 The WooCommerce Recargo de Equivalencia plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
35c4a9c5-a8aa-4b05-9968-76060b4fad20
< 1.79.274
MEDIUM 4.3 The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to Cross-Site Request Forger… wordfence
35b5a51d-e617-4f89-b663-36b73db93a59 MEDIUM 4.3 The Custom Login and Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
35b3a82a-4391-41b0-b434-691743c5ff4d
< 3.11.2
MEDIUM 4.3 The Fusion Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
35b1fb1a-a12c-4938-a2d2-74e291db76ef
< 3.1.2
MEDIUM 4.3 The Leopard - WordPress Offload Media plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
35b02e79-9d31-482a-92b9-b1e8201d45f1 MEDIUM 4.3 The Ni WooCommerce Customer Product Report plugin for WordPress is vulnerable to unauthorized modification of data due t… wordfence
← Prev 1529 1530 1531 1532 1533 1534 1535 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top