πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1544 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2930dda1-604a-454b-b858-6bb6a2bfdcdb
< 2.9.1
MEDIUM 4.3 The Link Whisper Premium plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
292be50c-6eab-4462-b46c-c7763e8aa223
< 2.1.3
MEDIUM 4.3 xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor rol… wordfence
291f8213-71e4-41d6-8db5-2dab6bfbaeef MEDIUM 4.3 The Google SEO Pressor for Rich snippets plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
29161530-1ffa-48d0-98a9-fa68a0b1a057
< 1.0.9
MEDIUM 4.3 The Polls CP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.8. T… wordfence
291085c8-a8e5-4401-963e-5268b25859ed MEDIUM 4.3 The Effect Maker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
28e9d339-b304-45c1-95ae-cb4c13703bfc
< 1.6.3
MEDIUM 4.3 The AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot plugin for WordPress is vulnerable to Cross-Site Reque… wordfence
28e48604-2aaf-4e02-9b1e-cebf5f0bfcf7
< 1.2.0
MEDIUM 4.3 The CP Image Store with Slideshow plugin for WordPress is vulnerable to authorization bypass in all versions up to, and … wordfence
28e2a490-aac7-485f-89f6-b8b779625b86 MEDIUM 4.3 The Lottier plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
28dea1e9-e772-488e-b98f-93a46ab84581
< 4.4.7
MEDIUM 4.3 The WP Travel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.6. … wordfence
28d622b3-e8a7-4a3b-9f0b-e344b085284d MEDIUM 4.3 The easy-popup-show plugin for WordPress is vulnerable to Cross-Site Request Forgery in version all versions. This is du… wordfence
28d47605-ecb8-42cc-901a-3cf07b946877
< 2.3.0
MEDIUM 4.3 The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
28d0ecb6-18ee-4c89-bc1d-541e9803c62c
< 3.1.9
MEDIUM 4.3 The Stock Locations for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
28ca150a-443f-4b99-8c15-491bd9f1cee3
< 1.0.105
MEDIUM 4.3 The Search in Place plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capabili… wordfence
28b70c72-3f09-4bb1-8655-831067f413ca MEDIUM 4.3 The Track Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
28a8b3fe-6f15-4085-a370-a2e867f7018b
< 2.1.15
MEDIUM 4.3 The WP Tabs plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.14. T… wordfence
28a4c868-a24d-4fd8-ae0e-d5c0bf3a7436
< 1.2.3
MEDIUM 4.3 The WP PDF Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
28a071ac-37ee-4fb9-b8c6-0a782ee673b4 MEDIUM 4.3 The Petje.af plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 2.1.8.… wordfence
2896c925-e035-4193-92db-e8a3dd34a0b7 MEDIUM 4.3 The Blog Introduction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
287abdef-24de-4e1b-a673-59cd37411bf6
< 1.2.0
MEDIUM 4.3 The Themify Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
2876064d-985a-4398-aa08-dd29c8437ae9 MEDIUM 4.3 The Wp Easy Allopass plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
285d2b85-cdd0-4447-8cdc-b641751e4a5f
< 1.160
MEDIUM 4.3 The Cincopa video and media plug-in plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
284d72cd-8859-4704-9242-e28e592b0475
< 2.12.3
MEDIUM 4.3 The Football Pool plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
28438010-0801-45c6-bf03-86dc93830a12
< 2.2.2
MEDIUM 4.3 The LifePress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
281ebead-5a30-4bfb-8280-94faf5d4fc14
< 2.4.5
MEDIUM 4.3 The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowi… wordfence
280e1b4d-08be-4e77-abcb-5f9079111595
< 8.7.4
MEDIUM 4.3 The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability c… wordfence
← Prev 1541 1542 1543 1544 1545 1546 1547 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top