πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1540 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2da3b5f4-4524-484a-9a91-32867446574a
< 4.20
MEDIUM 4.3 The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
2da322ea-0206-4838-8ac4-9dd201bb00bc
< 2.1.2
MEDIUM 4.3 The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
2d7be70b-ac33-4fc2-a627-52f238c2011e
< 7.6.7
MEDIUM 4.3 The GamiPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.6.6. … wordfence
2d66d939-7679-4831-9bce-104b71e997a8 MEDIUM 4.3 The Werkstatt - Creative Portfolio WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in ve… wordfence
2d62c49c-3a33-4865-abcc-22d8e38ac198 MEDIUM 4.3 The Ni WooCommerce Order Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to a… wordfence
2d4965e5-c207-475e-9673-29b3d0d996f7
< 2.6.5
MEDIUM 4.3 The StoreCustomizer – A plugin to Customize all WooCommerce Pages plugin for WordPress is vulnerable to unauthorized a… wordfence
2d3e2880-bb86-4263-9ed4-25a9769890e4
< 1.3.3
MEDIUM 4.3 The Supervisor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
2d3b9cde-e4d8-4217-96b4-f6ad00cd3a2d
< 19.1.11
MEDIUM 4.3 The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-S… wordfence
2d36fa25-108b-462b-b84e-2e77943b1871
< 1.9
MEDIUM 4.3 The TextP2P Texting Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and in… wordfence
2d33a880-0238-4d27-a433-6a09844bef3f
< 3.2.6
MEDIUM 4.3 The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
2d2f543b-ade7-4908-ac8a-e46a1d59d481
< 5.10.5.1
MEDIUM 4.3 The TheGem theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
2d21fe88-a273-410a-99c6-5ec576b187b9 MEDIUM 4.3 The Heateor Social Login WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
2d10475f-83dd-4e59-83e4-aeaa72a22b96
< 1.1.4
MEDIUM 4.3 The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to … wordfence
2d1010bf-8c96-4007-bebe-6df38e3c19ba
< 5.116.0
MEDIUM 4.3 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… wordfence
2d0a9410-533a-4d5a-859c-fc9ad839f47a
< 2.0.4
MEDIUM 4.3 The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Sensiti… wordfence
2d08e462-8297-477e-89da-47f26bd6beae
< 3.1.14
MEDIUM 4.3 The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
2cff84a4-9264-4789-997b-bc11a8bac449
< 3.8.2
MEDIUM 4.3 The Ultimate Product Catalog plugin for WordPress is vulnerable to authorization bypass due to a missing capability chec… wordfence
2cfd4a2c-750e-45db-9bca-8dae4668be53
< 1.2.8
MEDIUM 4.3 The WP AI CoPilot – AI content writer plugin, ChatGPT WordPress, GPT-3/4 , Ai assistance plugin for WordPress is vulne… wordfence
2cee1253-52e5-4676-8a7a-ac71df0786ed
< 1.4.5
MEDIUM 4.3 The Post Views Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
2cc50690-ef5d-4890-9d20-a90fea712ddf
< 1.3.7
MEDIUM 4.3 The Trust Payments Gateway for WooCommerce (JavaScript Library) plugin for WordPress is vulnerable to Cross-Site Request… wordfence
2cba74f7-7183-4297-8f04-4818c01358ef
< 1.7.2
MEDIUM 4.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized loss of data due to a missing … wordfence
2cb5370f-14aa-445d-bda3-62a0dd068fc5
< 6.15.15.3
MEDIUM 4.3 The Website Builder by SeedProd plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
2ca9b3e2-bb3a-44e0-8bff-0c9365449ce4
< 5.3.59
MEDIUM 4.3 The Calculated Fields Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
2ca6746d-afca-4ade-bd2e-4d37dedd3c5c MEDIUM 4.3 The MPWizard – Create Mercado Pago Payment Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
2c8a6ff9-6aa8-4e0f-b058-759561a55508
< 2.8.20
MEDIUM 4.3 The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing cap… wordfence
← Prev 1537 1538 1539 1540 1541 1542 1543 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top