πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1535 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3386ea07-9c61-4b54-a451-1178ca6325cb
< 5.4.5
MEDIUM 4.3 The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… wordfence
3386e24f-5861-4115-96ea-a47cd65a560f
< 1.2.5
MEDIUM 4.3 The Element Invader – Template Kits for Elementor plugin for WordPress is vulnerable to unauthorized access due to a m… wordfence
338158b5-bbda-4cd8-b4ea-97a3926a0989
< 4.3.5
MEDIUM 4.3 The Ninja Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.… wordfence
33800fbb-7660-4704-a978-d5b64ff9f66e
< 2.7.4
MEDIUM 4.3 The Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Part… wordfence
337bb11f-dcab-4914-aeb4-68084504b8f9
< 1.8.13
MEDIUM 4.3 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
33735219-3e12-4a8b-87af-99d7a836e9fa MEDIUM 4.3 The Widgets Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
3371df49-aecc-4442-9b8c-58e3c7e26752 MEDIUM 4.3 The WebinarPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
3354b925-2e4a-4ee5-b436-2c1a502b1725
< 3.39
MEDIUM 4.3 The NextGEN Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… wordfence
335402dd-5c18-4927-aa59-9683003064ca
< 3.1.12
MEDIUM 4.3 The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all … wordfence
33275cdc-21d4-42b7-bd0e-f5154faf2d6c
< 1.2.3
MEDIUM 4.3 The Comments Like Dislike plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including… wordfence
331a893c-498d-4ae8-8a04-e7aa25640e80 MEDIUM 4.3 The Theme Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
330e40d9-56b2-446a-8aa9-22a59e17c122
< 1.4.6
MEDIUM 4.3 The Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator plugin for WordPress is … wordfence
330e236b-410e-43c3-8a9f-216e3f177789 MEDIUM 4.3 The Contact Form, Drag and Drop Form Builder Plugin – Live Forms plugin for WordPress is vulnerable to unauthorized ac… wordfence
3301899e-5c38-4ecd-b095-6e00b0f7582e
< 3.75
MEDIUM 4.3 The MyCurator Content Curation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
32fe8a09-b08f-42dc-b436-96a6ea50a439
< 1.12.04
MEDIUM 4.3 The xili-tidy-tags plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
32ee3eb8-18b7-47da-b4f9-cb252ffabc71 MEDIUM 4.3 The Quiz Expert – Easy Quiz Maker, Exam and Test Manager plugin for WordPress is vulnerable to Cross-Site Request Forg… wordfence
32ec6291-cd65-4244-8990-c536e812673e
< 9.2.09.002
MEDIUM 4.3 The Photo Album Plus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
32c7a2fb-8390-4ae0-9a12-113250b1969e
< 3.1.0
MEDIUM 4.3 The Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons plugin for WordPress is vulnerable to unauth… wordfence
32c2a25d-e660-4700-8df3-b043cf6aa78a
< 1.0.14
MEDIUM 4.3 The WordPress Live Chat Plugin for Elementor – LiveChat plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
32ad6b52-1d59-4458-9661-3f1f126163ca
< 6.5.0
MEDIUM 4.3 The PDF for Elementor Forms + Drag And Drop Template Builder plugin for WordPress is vulnerable to unauthorized access d… wordfence
32a1d281-cc98-4e63-80f5-4f89104f9377
< 1.36.0
MEDIUM 4.3 The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to Sensitive Information Ex… wordfence
329a7910-fc9e-4786-9f0e-84eeb6e48bf4
< 3.4.2
MEDIUM 4.3 The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arb… wordfence
328fc7a9-be41-4e30-bb8d-c12ac3fd63f5
< 2.14.2
MEDIUM 4.3 The Zoho Flow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.14.1.… wordfence
328d65f4-422c-4c96-ad5d-b02b596aa998
< 2.3.0
MEDIUM 4.3 The Dynamic Pricing and Discount Rules plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
328ccf8f-797b-4b1a-b0f1-afd8e44f41e6
< 1.53.2
MEDIUM 4.3 The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includ… wordfence
← Prev 1532 1533 1534 1535 1536 1537 1538 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top