πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1534 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
348eb3f1-fa8e-42ae-b8a7-a1de3d196acf
< 4.21.0
MEDIUM 4.3 The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, … wordfence
3477baf1-71ef-44f3-938f-3e7d710e9df6
< 0.96.0
MEDIUM 4.3 The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … wordfence
346049ca-1bc5-4e02-9f38-d1f64338709d
< 3.4.4
MEDIUM 4.3 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sendin… wordfence
34603c3f-834f-4a2a-9b9f-5213155d4317
< 8.72
MEDIUM 4.3 The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… wordfence
344ad959-038a-46d1-b515-ae3473af8209
< 1.5.8
MEDIUM 4.3 The Educenter theme for WordPress is vulnerable to unauthorized plugin activation due to a missing capability check on t… wordfence
3444c4b0-4619-482f-8313-d3006aa1e845
< 2.5.2
MEDIUM 4.3 The Custom Field Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
342ece60-faf1-4fee-bf1e-6f6107f32861
< 1.1.6
MEDIUM 4.3 The HelpDesk contact form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
342d90e1-9d2e-4262-9667-013a8506727b
< 4.5.15
MEDIUM 4.3 The Helpful plugin for WordPress is vulnerable to repeat voting in versions up to, and including, 4.5.14 due to insuffic… wordfence
340f3e7b-6af3-4a16-817d-378324fb8cf0 MEDIUM 4.3 The Domain Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
34062e9a-48c2-4676-ab7d-b6334f248e8a
< 1.4.104
MEDIUM 4.3 The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure us… wordfence
33ff0508-4acd-427c-a2d3-53b808cc63ee
< 1.1.3
MEDIUM 4.3 The Hive Support – WordPress Help Desk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
33fdd325-2a9e-4049-a2b0-c3eddc773c96
< 1.6.1
MEDIUM 4.3 The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized access due to … wordfence
33fd44dc-b4f8-4429-8dcd-5161602bb318 MEDIUM 4.3 The I Am Gloria plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
33f5a513-bc98-4beb-bec2-72eba8bd783d MEDIUM 4.3 The Style Kits plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
33f3c466-bdeb-402f-bf34-bc703f35e1e2 MEDIUM 4.3 The Amazonify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8… wordfence
33f335ef-7cf5-4056-a8bb-f64b3f54eded
< 4.15.3
MEDIUM 4.3 The oik plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.15.2. T… wordfence
33efcbb4-2bb9-4414-bc95-55bedb92c551 MEDIUM 4.3 The Stout Google Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
33d08b1a-3933-4131-b7b5-3530612d2157
< 1.1.1
MEDIUM 4.3 The DefendWP Firewall plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the… wordfence
33b98bee-7f33-4d49-96e1-9a1eafc92bb3 MEDIUM 4.3 The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss … wordfence
33ac910c-9531-45ea-84cf-1d379233f7d3
< 2.4.5
MEDIUM 4.3 The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check… wordfence
33a801ab-b86f-42b3-bb79-dad64617a56a
< 2.2.81
MEDIUM 4.3 The FluentSMTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.80… wordfence
33a54cae-0fa3-4c25-bf81-8423f5e01e84
< 2.2.2
MEDIUM 4.3 The Debug Log Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check … wordfence
33a47156-ee93-4b59-9f73-56be5c9e3b00
< 1.2.8
MEDIUM 4.3 The Featured Post Creative plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce verific… wordfence
339c4eba-fa34-4db6-be4b-bcf0ba98121a
< 1.4.9
MEDIUM 4.3 The WordPress Backup & Migration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa… wordfence
3391d3dd-572e-4238-bfa6-f54db0b1fec4
< 3.0.97
MEDIUM 4.3 The Rank Math SEO PRO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
← Prev 1531 1532 1533 1534 1535 1536 1537 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top