πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1543 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2a59e1f6-1ffd-4ff7-83dd-8bf3121bb875 MEDIUM 4.3 The Sparkle FSE theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
2a3056d4-5ee9-4b31-9ef8-0e55f470ad23
< 1.13.3
MEDIUM 4.3 The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
2a2124be-358c-47af-97c2-02afbed91a3b
< 2.0.4
MEDIUM 4.3 In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient… wordfence
2a1b7e37-1e30-473c-aadc-176de729e619
< 2.52
MEDIUM 4.3 The Simple Author Box plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and incl… wordfence
2a0d07a1-2548-48f5-b9c1-49838ae74053 MEDIUM 4.3 The Generate Post Thumbnails plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
29f6e37a-1f73-480e-984b-c24e2eaa55f5
< 4.1.4.1
MEDIUM 4.3 The Uncanny Toolkit Pro for LearnDash plugin for WordPress is vulnerable to unauthorized modification of data due to a m… wordfence
29e9cbca-5ed1-4619-a2a7-60b0f001e8d9
< 4.1.3
MEDIUM 4.3 The SMS Abandoned Cart Recovery ✦ CartBoss plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
29e2ff11-053b-45cc-adf1-d276f1ee576e
< 2.2.2
MEDIUM 4.3 The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
29d430a7-e730-412f-b4cf-16505975f856 MEDIUM 4.3 The GPP Slideshow plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
29d112ca-c793-4459-a5a0-7f1a3de9de71
< 2.1.0
MEDIUM 4.3 Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to import… wordfence
29c762c7-7bb9-42bc-9e22-0f4da2a5c59b
< 2.6.87
MEDIUM 4.3 The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to unauthorized acces… wordfence
29b81e96-d950-405a-abcb-c457e104b86b MEDIUM 4.3 The Crony Cronjob Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
29b0fd97-a669-42bb-b01e-bdc0395d697e
< 4.2.2
MEDIUM 4.3 The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data du… wordfence
29abbd93-b353-4cf1-9027-0825e1a2aa3d
< 3.0.3
MEDIUM 4.3 The RSS Feed Widget plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
299ed515-ba64-413a-a03a-2db801520ae0
< 1.0.0
MEDIUM 4.3 The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… wordfence
2996c61b-9537-40d1-b652-a4f7a9066966 MEDIUM 4.3 The Spoter for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
2990f542-29a8-49d6-aa92-455208b935f1 MEDIUM 4.3 The Virtual Moderator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
2972cdaf-2d0a-4b55-b4f5-ccf01ff5352c MEDIUM 4.3 The Contact Form 7 Style plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
2971344c-4162-4d44-90cb-28a922fdb909 MEDIUM 4.3 The Hello FSE Blog theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
29700844-b41d-4f10-90a7-06c8574d8d2a
< 2.7.10
MEDIUM 4.3 The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
296f15eb-0782-4351-a2c5-c8ef6f005352
< 3.25
MEDIUM 4.3 The TrustProfile plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.24… wordfence
2959ae2f-ef16-45d8-920f-56b141ad955e
< 6.0.1
MEDIUM 4.3 The Float menu – awesome floating side menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve… wordfence
2952a7bf-ccbf-46e0-ac7e-54576f413f66 MEDIUM 4.3 The Alphabetical List plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
293480b2-3160-4361-98d4-ed6e601d53c4
< 2.1.6
MEDIUM 4.3 The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
29333999-ffe3-4cd0-a537-be98168cb2ee
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
← Prev 1540 1541 1542 1543 1544 1545 1546 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top