πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1536 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
328bc382-f562-46cc-9d6d-74279f2fa9d3 MEDIUM 4.3 The Subscribe To Unlock plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
32832d82-8d23-4825-8d31-71d223eaceed MEDIUM 4.3 The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to Cross… wordfence
32713069-ea40-46ef-a789-9646eab2e651
< 8.2.1
MEDIUM 4.3 The WP Customer Area plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
32701ae6-004c-41e2-bdf0-d78c6c2b3e97
< 12.4.17
MEDIUM 4.3 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc… wordfence
3267ca02-341a-4fb6-b7f1-08094bff0eb0
< 3.8
MEDIUM 4.3 The HR Management Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
32647c44-389a-4a6d-a32b-e19a35bc2aeb MEDIUM 4.3 The Auto Excerpt everywhere plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
325298a6-954b-4cf7-a96a-9571cdb0b5a5
< 1.3.3.2
MEDIUM 4.3 The WordPress Meta Data and Taxonomies Filter (MDTF) plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
32506176-6e74-4889-9cbd-111a57980b0c
< 4.3.7
MEDIUM 4.3 The Contact Form by BestWebSoft plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
3223a1c0-e0e3-46e6-ba4c-777db86bdb26 MEDIUM 4.3 The Slides & Presentations plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
32173d38-7f85-4e0c-9b4c-38bee2783d77
< 8.1.16
MEDIUM 4.3 The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
32112d1b-4213-4eea-89d6-4bda41d32c9f MEDIUM 4.3 The Countdowner for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
31f6ee4e-2106-42c8-8d52-0ce8e415c55f
< 1.1.0
MEDIUM 4.3 The Heureka plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8… wordfence
31f24e61-4bb1-4159-bfd0-8598fc082801
< 2.23.2
MEDIUM 4.3 The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerabl… wordfence
31dfc46c-a673-41f1-b701-aa832f004ebc
< 7.6.2
MEDIUM 4.3 The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the dup… wordfence
31d2ccd2-d38b-4bdf-a905-a2b54ca80a58 MEDIUM 4.3 The Hide My Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… wordfence
31c6a879-0b90-44d7-9932-7a6acb25516d
< 2.0.16
MEDIUM 4.3 The Unlimited Elements For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… wordfence
31c5e524-ef4d-48c7-baa0-595f8060a167
< 1.1.4
MEDIUM 4.3 The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du… wordfence
31c2cd54-f258-43ea-8db2-8d98ad7014d1
< 5.9.7.3
MEDIUM 4.3 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspen… wordfence
31a66e30-972b-4a7b-9d47-ad7abd574e36
< 1.7.4
MEDIUM 4.3 The Image Watermark plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
31a3a3c1-be0e-46d5-9fa3-563febc5569b MEDIUM 4.3 The Mail Bank - #1 Mail SMTP Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of dat… wordfence
319cccd5-fe76-4986-af4c-3132a09a2686
< 1.0.101
MEDIUM 4.3 The Vehica Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
317b1bac-cd9c-4eac-b42b-d7719ecd135c
< 1.3.9
MEDIUM 4.3 Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.8 allows… wordfence
316f1771-6c61-4ef9-aa6a-73e61acc43af MEDIUM 4.3 The Custom Dashboard Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
316b807c-06ca-4448-acb9-80766a07258a
< 8.3.1
MEDIUM 4.3 The Mortgage Lead Capture System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
3169d0e6-3e0a-49ca-9e39-c587f88209fa MEDIUM 4.3 The Woocommerce Gifts Product plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
← Prev 1533 1534 1535 1536 1537 1538 1539 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top