πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1547 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
25dd83c5-2ebe-4976-8e97-650e5eadbe43
< 1.1.3
MEDIUM 4.3 The Portfolio Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
25b3607c-f99e-4359-8228-0f3452f80aac MEDIUM 4.3 The Table Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
25a500fe-c048-482c-b0cb-262ae25cedc6
< 1.4.1
MEDIUM 4.3 The WP Mobile Bottom Menu plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
259e80a0-21e8-4482-89dc-899a08669e91 MEDIUM 4.3 The WP Logs Book plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
259a4950-9377-4d18-86ad-aadd97dcdbc7
< 2.0.4
MEDIUM 4.3 The Add Custom Fields to Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
257c30a3-81b6-4efe-89fd-adbbeb495f48
< 7.5
MEDIUM 4.3 The Cost Calculator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
257052f4-2b0a-4604-befd-651dc338b3d5 MEDIUM 4.3 The LOGIN AND REGISTRATION ATTEMPTS LIMIT plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
25687ee6-a899-4089-966b-69578afd3fb6
< 7.33.1
MEDIUM 4.3 The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of s… wordfence
255546b4-4e0e-479a-8414-1f8c7192de51 MEDIUM 4.3 The WP Video Playlist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
2548d5b0-1f1a-4847-a5ea-e3bb6f7a5013
< 1.2.8
MEDIUM 4.3 The Astra Bulk Edit plugin for WordPress is vulnerable to unauthorized missing authorization due to a missing capability… wordfence
25441444-f19c-4a68-9a2d-37c61189f457 MEDIUM 4.3 The Carter for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
254291b3-a30d-44ff-9df4-6ba700a9efc9
< 2.2.1
MEDIUM 4.3 The Schema App Structured Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
253d4985-d00e-40d4-b07c-42e613b4e53a MEDIUM 4.3 The Logo Manager For Samandehi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
252153ec-3811-484a-984f-eeb6ed9229a5
< 0.3.9
MEDIUM 4.3 The CSV Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.3.… wordfence
25031afe-5c23-45e2-a6b5-61189bfe5047 MEDIUM 4.3 The adstxt Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
24fb24cc-c29f-4d2d-87ba-5d211386e7dd
< 3.3.7
MEDIUM 4.3 The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl… wordfence
24f13f9a-b240-4e32-9f12-117dbe7ecac4
< 3.7.4
MEDIUM 4.3 The Multivendor Marketplace Solution for WooCommerce plugin for WordPress is vulnerable to users commenting as a differe… wordfence
24ef5844-93d6-4ba3-bd0a-b8837bbd7baf MEDIUM 4.3 The Frontier Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.1… wordfence
24e2b96c-665f-4616-ac99-1a2b1b0a9ccd
< 3.7.1
MEDIUM 4.3 The DoLogin Security plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… wordfence
24d84e7c-7a7a-4b29-95ee-60718c48840f MEDIUM 4.3 The auto making JSON-LD plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
24cdd50f-742c-457c-85f7-9cccaf366e87
< 3.7.8
MEDIUM 4.3 The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct … wordfence
24ccc2cb-3c5d-48cd-bc40-2717145b4912
< 1.2.5
MEDIUM 4.3 The Countdown Timer block – Display the event's date into a timer. plugin for WordPress is vulnerable to Informat… wordfence
24cad8ef-f0c4-4306-bd8e-4ce59baa424d
< 1.4.0
MEDIUM 4.3 The Integration for Contact Form 7 and Salesforce plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… wordfence
24be03a7-4632-4bb1-beb9-d83abdd363b9 MEDIUM 4.3 The Libsyn Publisher Hub plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
24b9984c-ec33-4492-815b-67a21ac4da0e
< 3.6.7
MEDIUM 4.3 The WP Customer Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and incl… wordfence
← Prev 1544 1545 1546 1547 1548 1549 1550 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top