πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1546 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
26ed5016-48f7-44cf-af59-0c95a90bd473
< 1.0.2.4
MEDIUM 4.3 The wordpress publish post email notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve… wordfence
26d8b75b-befa-4c6a-b072-0da44e437174
< 1.1.4
MEDIUM 4.3 The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du… wordfence
26d70dee-c098-40f1-962a-db56791ae221
< 5.2.6.0
MEDIUM 4.3 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
26d28cb4-3cbd-4baf-968a-a3d37693306f
< 2.3.3
MEDIUM 4.3 The Clearfy Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3… wordfence
26ccf502-192b-4018-8876-d415c7fb27cc
< 3.2.21
MEDIUM 4.3 The Strong Testimonials plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
26b64ae3-5839-47d5-9c65-7c595bb18e6c
< 2.1.60
MEDIUM 4.3 The Total theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th… wordfence
26ae90f9-3efe-4ae4-b309-3af524a27828
< 0.19.1
MEDIUM 4.3 The Theater for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
26a246c3-cf67-4566-b1e8-dc14c3c5c827
< 2.0.6
MEDIUM 4.3 The Radio Buttons for Taxonomies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
267c7c4b-3598-45d8-8b32-7266e8bee527 MEDIUM 4.3 The Developer Tools Blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
2677128e-6da2-4c5e-a8ee-17c290d72c8a
< 2.10
MEDIUM 4.3 The WPGraphQL plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
2675fa78-4236-4574-8c81-ff3bce11ff9d
< 2.2.0
MEDIUM 4.3 The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
267119ab-4129-4c27-bfaf-0b9916623695
< 3.0.11
MEDIUM 4.3 The Feedweb plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the ~/feedwe… wordfence
2655f936-8177-4836-a0b0-1c637290a3bc
< 3.34
MEDIUM 4.3 The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
2645899c-2b6b-48bd-8f33-2a837a951c5e MEDIUM 4.3 The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.1… wordfence
263153c9-61c5-4df4-803b-8d274e2a5e35
< 1.7.2
MEDIUM 4.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
263029e3-68ef-416b-97f4-187647b9502d
< 14.15.2
MEDIUM 4.3 The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthori… wordfence
2621d2f1-7ce3-4858-9633-080ef916d374
< 14.1.00
MEDIUM 4.3 The WZone plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
2620da78-3d78-40c5-a125-09d93993cac8
< 2.16.10
MEDIUM 4.3 The Seraphinite Post .DOCX Source plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
2612f883-0275-4f68-aacf-f97c1df96230
< 2.3.18
MEDIUM 4.3 The Post Grid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
26110187-2d74-4c6e-9ca5-618015beaab4 MEDIUM 4.3 The Service Finder Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
26100f1f-3224-486c-b4f9-7086d405a883
< 1.4.27
MEDIUM 4.3 The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access o… wordfence
25ff4093-f8bf-41f8-b9d8-c15ecee71b43 MEDIUM 4.3 The Import external attachments plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
25fa3c6b-d680-4c08-a183-4dc31bcb799e MEDIUM 4.3 The Elevio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.1.… wordfence
25f8b0db-eed2-468a-a6b3-ed93daaddcb2
< 1.26.1
MEDIUM 4.3 Reflected Cross-site scripting (XSS) vulnerability in the Max Foundry MaxButtons plugin before 1.26.1 for WordPress all… wordfence
25f0615b-17a1-4bf8-9f77-4703c39baca5
< 3.3.04
MEDIUM 4.3 The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
← Prev 1543 1544 1545 1546 1547 1548 1549 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top