πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1537 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3164b96f-d876-4cbc-bddf-51e9d9becee6
< 4.2
MEDIUM 4.3 The SKT Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
31612b4b-a75f-4fa4-831b-43f62a8d5fad
< 1.2.8
MEDIUM 4.3 The Database Collation Fix plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
31589d0c-42bc-4657-ac6a-ce236e427211
< 5.0
MEDIUM 4.3 The Add Custom Codes plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
3152208e-e4f7-4f48-b6a1-05a656d9c826
< 3.2.0
MEDIUM 4.3 The Peach Payments Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
3150785b-911b-44d8-aa85-afffce19c08e MEDIUM 4.3 The Activity Plus Reloaded for BuddyPress plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
314d3e0c-ba29-4795-a646-40e0acfc3405
< 2.3.8
MEDIUM 4.3 The Clone plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.7. This… wordfence
314ae0f5-8a4e-4bf3-9fc9-49f5b036b99e
< 4.25.0
MEDIUM 4.3 The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability … wordfence
313db01b-8ee8-4df1-9a86-0de1bad46921
< 2.7.9
MEDIUM 4.3 The WP Migrate Lite – Migration Made Easy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
313b5634-20c6-4666-be96-ce59fa4366ac
< 1.2.54
MEDIUM 4.3 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordP… wordfence
313b3629-3bbb-4d96-a96c-e6fa2ef498a0
< 0.18.8
MEDIUM 4.3 The Theater for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
3122b2f6-9ea9-41ca-914d-8a04ea18df6c MEDIUM 4.3 The WP Security Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
30f2dd33-228d-4942-88d9-78c7ed0b79a1
< 2.1.1
MEDIUM 4.3 The Frontend User Notes plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an… wordfence
30e0289c-b893-41bd-aad9-d7ec62bf2b23
< 6.3.1
MEDIUM 4.3 The The Events Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
30cf9783-6422-43f8-b5dc-a613a9513296
< 6.2.2
MEDIUM 4.3 The Easy Appointment Booking & Scheduling System – Webba Booking Calendar plugin for WordPress is vulnerable to unauth… wordfence
30ce93b4-9e2a-4a8c-8590-ffd61d618d31
< 1.2.2
MEDIUM 4.3 The Instant CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1… wordfence
30c99510-fd57-4268-8e35-6f7e6f912b7e MEDIUM 4.3 The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized modification of… wordfence
30bb6746-a11b-4e59-b2ae-b0133580c9db MEDIUM 4.3 The car-park-booking-system-for-wordpress plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
309e0ebe-8873-46a1-ae82-d3bd05e68d00
< 1.8.5.4
MEDIUM 4.3 The Content Mask plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu… wordfence
309b33eb-678a-48f5-9793-042cbcda9984 MEDIUM 4.3 The Rosebud - Flower Shop and Florist WordPress Theme theme for WordPress is vulnerable to Insecure Direct Object Refere… wordfence
308c9d72-4739-4fcd-8e04-b24edc19ec06 MEDIUM 4.3 The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
30881bed-9a5c-4a7f-9065-f11a1b336892
< 8.4.6
MEDIUM 4.3 The Soledad theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
307bbfe6-8a57-461d-aa7d-bce962da4239 MEDIUM 4.3 The Vertical scroll recent post plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
3071b2dc-9673-4e30-bd04-7404eb6a1ed9
< 2.37
MEDIUM 4.3 The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.3… wordfence
304ed5df-27a4-4fd3-b572-51017142b510 MEDIUM 4.3 The BP Disable Activation Reloaded plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
302c4eb3-d30e-4140-b674-e62b886d1618 MEDIUM 4.3 The AP HoneyPot WordPress Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
← Prev 1534 1535 1536 1537 1538 1539 1540 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top