🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1533 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
35a8ca49-6d23-43c1-a14a-0aa9f7214e73
< 8.2.0
MEDIUM 4.3 The WPBot AI ChatBot plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
35a7caac-1171-474a-86c6-7893658c91eb MEDIUM 4.3 The EasyIndex plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.170… wordfence
35a75451-f0ae-4630-b415-394c76868e93
< 3.3.1
MEDIUM 4.3 The Max Mega Menu plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the san… wordfence
35a0a0b8-2d62-4675-9bec-d26164271a03
< 4.2.0
MEDIUM 4.3 The WP Shamsi plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when saving p… wordfence
359ab91d-5b60-460b-b6f2-90a5afa675ea
< 1.2.5
MEDIUM 4.3 The Automatic Featured Images from Videos plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
359aae96-8b6d-4365-b0c1-f0c7220383c9
< 2.2.1
MEDIUM 4.3 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access du… wordfence
3595f1c7-22a5-46c6-b81f-fe616a71116f MEDIUM 4.3 The Visual Sound (old) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
35934e53-4ef0-4b05-94a7-d67fbf57f312
< 2.4.0
MEDIUM 4.3 The ELEX WooCommerce Request a Quote plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… wordfence
35906df7-5eaf-494a-8184-48e2ca22301e MEDIUM 4.3 The EasyRecipe plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.32… wordfence
3586da3d-fec0-4890-8918-bc1c417e44f7
< 1.7.1
MEDIUM 4.3 The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to Cross-Site Reques… wordfence
356cf06e-16e7-438b-83b5-c8a52a21f903
< 3.3.2
MEDIUM 4.3 The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name'… wordfence
35499ef6-c36b-4c5b-9cca-e7aaeec3a5e3
< 3.11.10
MEDIUM 4.3 The ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulne… wordfence
3544357f-97c9-49cb-a48d-74b60480111d
< 9.0.6
MEDIUM 4.3 The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.… wordfence
35421b32-701a-4fc9-bcec-80684d874bab MEDIUM 4.3 The Unyson plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability … wordfence
353c244f-6d5d-47d6-988e-33da722a02f9
< 2.6.4
MEDIUM 4.3 The Mollie Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on … wordfence
352e705d-0233-40ef-a54e-91d42cdf432a MEDIUM 4.3 The Popup for CF7 with Sweet Alert plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
3504a30a-f818-4168-937a-1172f21cb8c6 MEDIUM 4.3 The Call Now PHT Blog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
34fb7647-76e2-4985-816e-c6420c01a048
< 4.4
MEDIUM 4.3 The Oxygen plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 4.4. This is due to missin… wordfence
34eaee0f-7a5b-4496-a5c8-5f6c69e24417
< 5.3.6
MEDIUM 4.3 The Customer Reviews for WooCommerce plugin contains several AJAX actions that are not protected by capability or nonce … wordfence
34e56098-490c-4ea1-8acf-e103f1d7f602
< 1.10
MEDIUM 4.3 The ShayanWeb Admin FontChanger | افزونه‌ی تغییر فونت پیشخوان وردپرس شایان وب plug… wordfence
34d990b6-3021-45d4-9ecd-cfabb7fbc96c
< 1.5.7
MEDIUM 4.3 The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
34cddc7b-575c-4494-afa0-cd85c7b313e9
< 1.0.17
MEDIUM 4.3 The WP Client Reports plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ… wordfence
34c0c676-37f9-49f2-ad50-2d70831fda53
< 3.2.3
MEDIUM 4.3 The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to Cro… wordfence
34b39462-32c5-4f7d-b54f-d95f40b6ed92
< 4.2.4
MEDIUM 4.3 The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
348faeed-0e08-4694-a800-891052376686
< 1.3.4
MEDIUM 4.3 The Tourfic Toolkit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
← Prev 1530 1531 1532 1533 1534 1535 1536 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top