πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1539 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2ec5eaf2-9519-42ef-a8b6-d80307c2a18d
< 1.3.7
MEDIUM 4.3 The WP Bulk Delete plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
2ec5d29e-43e2-4cd3-8164-94b01fab4d64
< 1.10.05
MEDIUM 4.3 The Autolinks Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
2ec0aeb4-e831-484b-8a9d-82ec0189a1b4 MEDIUM 4.3 The Hospital Doctor Directory plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
2eb963dd-41c3-43cd-afb7-1be054829ea3
< 2.9.44
MEDIUM 4.3 The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
2eb5683d-a787-47b2-a4fa-f769266bf5ec
< 3.0.4
MEDIUM 4.3 The aDirectory – WP Business Directory Plugin and Classified Ads Listings Directory plugin for WordPress is vulnerable… wordfence
2ea8d38a-f5ce-40dd-a015-f56d60579e05
< 3.6.2
MEDIUM 4.3 The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers… wordfence
2ea06520-d7a9-49bb-812e-2fa2e50d0ec2
< 8.6.1
MEDIUM 4.3 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in… wordfence
2e8da71c-bf53-4795-a689-5823d963cb82
< 2.0.10
MEDIUM 4.3 The HD Quiz plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
2e87cfc4-8e7c-47d6-80fc-9c293cdd8acb
< 1.2.12
MEDIUM 4.3 The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a… wordfence
2e7ebc0c-6936-4632-a602-7131c7d8bd6a
< 1.1.3
MEDIUM 4.3 The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing auth… wordfence
2e798eea-786a-43e2-b535-842ca666ff0f
< 1.5.8
MEDIUM 4.3 The Booter plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
2e63c0fb-7fe7-42f7-8fa9-ec159d3c8117
< 1.4.5
MEDIUM 4.3 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to… wordfence
2e617d6f-c1cb-4cac-88e2-3142c1ea9fab
< 2.7.3
MEDIUM 4.3 The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.2. … wordfence
2e470017-c453-435d-8342-66874a794537 MEDIUM 4.3 The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure i… wordfence
2e42dd1c-adf7-471a-a14a-9038c56413a2
< 5.8.3
MEDIUM 4.3 The Event Tickets and Registration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions … wordfence
2e3897fb-0f40-4111-8a7d-60415e1f9f96
< 2.0.0
MEDIUM 4.3 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post pu… wordfence
2e215a5c-7a01-4a1d-b051-3abf742bf573
< 1.2.8
MEDIUM 4.3 The Free WooCommerce Theme 99fy Extension plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
2e20a9d2-4bff-45ba-bffe-af82a7a4328d
< 1.6.5
MEDIUM 4.3 The ValidateCertify Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
2e1fbd52-32f8-48a3-9f25-2ab33350ee1f
< 1.3.3
MEDIUM 4.3 The CWW Companion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
2e1922c6-e63b-47aa-97de-1e2382fa25d3
< 5.7.0
MEDIUM 4.3 The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference … wordfence
2e1775fa-fb29-4ed7-8e39-ec834f0e6292 MEDIUM 4.3 The iNET Webkit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
2dfe5dd0-0dc9-4c64-8972-045325e5a54f
< 1.6.94
MEDIUM 4.3 The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
2dee184f-313e-40f8-9208-db51e6b73764
< 1.3.7
MEDIUM 4.3 The ContentStudio plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
2dd9df66-92de-4f25-8fdd-cb3bc0e6d529 MEDIUM 4.3 The replyMail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.0. … wordfence
2dc1f0c4-32fb-464e-939b-d565a5e1156c
< 1.4.0
MEDIUM 4.3 The GSheetConnector for WC plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
← Prev 1536 1537 1538 1539 1540 1541 1542 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top