πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1545 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
28062e5f-2a4c-419c-b0d1-3d91e72398e1
< 4.5.2
MEDIUM 4.3 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Sensitive Information Ex… wordfence
27eb0101-b3d1-458d-b7d7-69d92e3a4bb8 MEDIUM 4.3 The Comment Reply Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
27e7f9d1-a7c1-459b-996d-8fb02d3807cd MEDIUM 4.3 The WP Journal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
27e4d27f-b943-4cb3-b38a-01192844e9ac
< 4.2.16
MEDIUM 4.3 The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
27da9458-ac19-4b4e-a14b-d1ba62e9e9ea
< 4.3.0
MEDIUM 4.3 The WP OAuth Server plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on… wordfence
27ca0d04-9796-415f-a6e6-7c1752a74fea
< 1.3.0
MEDIUM 4.3 The Beebee Mini plugin for WordPress uses Advanced Custom Fields which has a file upload vulnerability in versions up to… wordfence
27c3d563-4ed5-47a1-ae2c-ff765fb56cb7
< 1.6.1
MEDIUM 4.3 The Read More Excerpt Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
27b599af-f1f6-48af-90fe-4fc23b17a4ae MEDIUM 4.3 The Advanced Custom Fields: Image Crop Add-on plugin for WordPress is vulnerable to Improper Authorization in versions u… wordfence
27b2d6d5-bd5b-4436-bec5-804cbb48abe1
< 7.9.3
MEDIUM 4.3 The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable t… wordfence
27b14c6e-44fe-4acb-8058-613f65b6baa4
< 1.6.4.6
MEDIUM 4.3 The Advanced Flat rate shipping Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
279314a4-2d70-4036-ae9a-27bb694b03db
< 4.9.0
MEDIUM 4.3 The which template file plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
278d22b7-fb13-4ee4-a462-ee86a289cbd4 MEDIUM 4.3 The Flytedesk Digital plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
27799988-cb2b-41c7-ad9a-aade59d31fa3 MEDIUM 4.3 The Automated Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
27695dd6-b063-43fe-886f-ce76cfd838cb
< 3.5.7
MEDIUM 4.3 The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
2761c5e9-7c4c-4257-9b55-587c02d07153
< 3.0.5
MEDIUM 4.3 wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) … wordfence
2760b183-3c15-4f0e-b72f-7c0333f9d4b6
< 6.1.0
MEDIUM 4.3 The WooCommerce EAN Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… wordfence
275812be-c931-4119-b0e4-2c45f71f5afc
< 9.7
MEDIUM 4.3 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object… wordfence
2756dcf4-715f-4a7b-855c-7347455e0323
< 1.7.20
MEDIUM 4.3 The Login with phone number plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
274429f7-1cd1-49e4-a145-dce36bebb9c2 MEDIUM 4.3 The Newsletter Popup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
27439d44-f2ff-4c20-965f-25d12c83781c
< 3.8.3
MEDIUM 4.3 The Happy Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
27332c13-c25f-47ec-980d-035fc35ce553
< 3.5.3
MEDIUM 4.3 The Easy Replace Image plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,… wordfence
272fc51d-aadd-4991-a308-3df8b62c35ac
< 5.6.0
MEDIUM 4.3 The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
2725df85-c24d-4570-95ca-0026e5f2ac90
< 2.3.16
MEDIUM 4.3 The Accordion – AI FAQ, Accordion, Tabs, Image Accordion, Product FAQ, FAQ Builder, FAQ Grid plugin for WordPress is v… wordfence
27161b4b-d11c-487b-b1ce-7e43bf7b2e57
< 3.1.6
MEDIUM 4.3 The Accept Stripe Donation – AidWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
26f73bfe-f41a-4045-9d72-21181a9a704f
< 3.6.9
MEDIUM 4.3 The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check… wordfence
← Prev 1542 1543 1544 1545 1546 1547 1548 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top