πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1542 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2b59d281-d5c8-455a-8aa8-b03847bdd45f
< 4.9.6
MEDIUM 4.3 The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
2b49add4-a4ae-4527-95bd-c295200eeedd
< 6.5.1
MEDIUM 4.3 The LiteSpeed Cache plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.4.1. Th… wordfence
2b4035c9-1ffa-465e-84cb-1c30bb4fb95c MEDIUM 4.3 The QR Code Tag for WC order emails, POS receipt emails, PDF invoices, PDF packing slips, Blog posts, Custom post types … wordfence
2b365fb8-7a93-4306-b2b1-ce47dc19457a
< 1.15.79
MEDIUM 4.3 The WooCommerce Bookings plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and i… wordfence
2b335807-f4d1-43b3-9e1b-2215eb00a3f8
< 3.1.5
MEDIUM 4.3 The WP Meteor Page Speed Optimization Topping plugin for WordPress is vulnerable to unauthorized admin notice dismissal … wordfence
2b300f55-f1ee-4345-adc2-32cd3b081a30
< 3.7.17
MEDIUM 4.3 wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before… wordfence
2b2b812d-b2bd-45d7-b712-482f41356764
< 17.4.0
MEDIUM 4.3 The Salient | Creative Multipurpose & WooCommerce Theme theme for WordPress is vulnerable to unauthorized access due to … wordfence
2b2a10b6-e7dc-47c7-9f59-c4350d58b0d1
< 0.1.0.25
MEDIUM 4.3 The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on sever… wordfence
2b249842-c480-495a-8eec-6c7d0893ef1c
< 3.2
MEDIUM 4.3 The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
2b229ea2-3a7d-42bd-a235-ffd18e206c8b
< 15.1
MEDIUM 4.3 The WP GoToWebinar plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on … wordfence
2af44b3e-62b4-4c27-8462-b2a82030a826
< 1.0.67
MEDIUM 4.3 The Skrill Official plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
2ae3aaf6-457f-4b7f-b3bb-b4028980ef55 MEDIUM 4.3 The Arabic Webfonts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
2ad0acd5-b5d8-481d-954e-a629bb0e11a8 MEDIUM 4.3 The Progressive WordPress (PWA) plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
2ac7414c-8035-406a-ab1e-94d9f64e52fa
< 1.4.15
MEDIUM 4.3 The PixTypes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.14. … wordfence
2ac3dd6c-6055-4a21-a4d2-e95ba5edc291
< 1.4.6
MEDIUM 4.3 The Groovy Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.5… wordfence
2abb66a3-67b9-48cb-acf1-18ee76eb3f70
< 6.0.1
MEDIUM 4.3 The Export WordPress Pages to Static HTML & PDF β€” Static Site Export plugin for WordPress is vulnerable to Cross-Site … wordfence
2ab58add-ab81-4c84-b773-7daf382492b0
< 3.2.3
MEDIUM 4.3 The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to una… wordfence
2a9ed6f2-3def-420c-b6d5-6343fcd7b147
< 3.1.4
MEDIUM 4.3 The Wise Chat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.3. … wordfence
2a8c62e6-f459-433a-b0c4-c79285ea7fe9
< 11.3.33
MEDIUM 4.3 The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information … wordfence
2a7d6059-4cef-4bd1-a14d-ad544bfaeea3
< 2.5.3
MEDIUM 4.3 The BetterDocs plugin for WordPress is vulnerable to unauthorized document modification due to a missing capability chec… wordfence
2a7b4c3c-a8a0-4f16-bfcb-5c2cd479fb9a
< 2.3.2
MEDIUM 4.3 The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
2a75f4eb-698b-4c92-9829-de6c55e21ecb MEDIUM 4.3 The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposu… wordfence
2a746ec6-c2fa-46ed-baf6-154659655235
< 2.5.4
MEDIUM 4.3 The Request a Quote Form Plugin – Price Quote Request Management Made Easy plugin for WordPress is vulnerable to unaut… wordfence
2a60d27b-dfcc-464e-a927-eb6bb35f9932 MEDIUM 4.3 The Frontend File Manager Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions … wordfence
2a5f4a74-3974-4d08-8238-387e573a5655
< 1.2.4
MEDIUM 4.3 The CM Table Of Contents – WordPress TOC Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
← Prev 1539 1540 1541 1542 1543 1544 1545 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top