πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1549 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
23b33b77-2e72-4959-bdce-646e968f2a73
< 5.0.50
MEDIUM 4.3 The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized mod… wordfence
23b21dbd-caf7-49fc-bed4-4017151ee4ad
< 9.1.10
MEDIUM 4.3 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of… wordfence
23b018d3-3451-4ae8-b571-07e931ad23df
< 1.6.6
MEDIUM 4.3 The Schema - All In One Schema Rich Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
23a56043-5dcb-435b-8fde-b09c52466c40
< 4.4.11
MEDIUM 4.3 The Paytium plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the p… wordfence
239dbe6b-3643-4d79-ab09-c3f7c53c6b0c
< 1.4.0
MEDIUM 4.3 The F12-Profiler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
23980e13-b632-43ec-938e-8171884cb87b
< 1.2
MEDIUM 4.3 The LIQUID SPEECH BALLOON plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
23924342-3b1d-4360-bd87-104091283e35
< 1.7.4
MEDIUM 4.3 The BuddyBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.… wordfence
238f6d81-78ba-426c-866a-31f9279e4f99
< 3.2
MEDIUM 4.3 The WP Private Content Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
2389eaae-374a-41c1-b28e-595841cda9a2
< 3.8.1
MEDIUM 4.3 The WP Mapa Politico EspaΓ±a plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
237b4427-56e8-45af-b932-3610acf3651f MEDIUM 4.3 The Simple Archive Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
236f5a78-435a-48d1-9dd7-c42a2155cb88 MEDIUM 4.3 The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.… wordfence
2368e46a-022c-4829-80f1-7d010e8587ed
< 10.3.5
MEDIUM 4.3 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized acces… wordfence
23689d5e-46a4-4387-8f49-1bf9a5e7c550
< 1.10.0
MEDIUM 4.3 The Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution plugin for WordPre… wordfence
236876d4-7838-400d-839a-ce257bf42645
< 1.8.0
MEDIUM 4.3 The Cooked – Recipe Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
236387f0-b58e-4ef1-b370-a0703a7902eb
< 3.3.94
MEDIUM 4.3 The Zephyr Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
23587460-1d9e-47d4-9077-67d15ee38ca6 MEDIUM 4.3 The Back To Top plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
2352dce7-5302-4892-9ae2-bf814f029af4
< 2.4.6
MEDIUM 4.3 The Classified Listing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
233a29f5-12bf-4849-9b28-4458a0b0c940
< 1.0.260
MEDIUM 4.3 The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
2339ebbf-2302-4e83-9743-ca79fda20f05
< 2.4.0
MEDIUM 4.3 The Wbcom Designs – Custom Font Uploader plugin for WordPress is vulnerable to unauthorized loss of data due to a miss… wordfence
2330b18e-0907-47e1-b91f-1fe466bcf76b
< 20.5.4
MEDIUM 4.3 The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable… wordfence
232e6464-bd6c-4086-989a-00b84056c431
< 1.4.3
MEDIUM 4.3 The Evergreen Content Poster plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… wordfence
232cdd3b-4683-4e95-bdfd-acf0f32aeb2a
< 1.3.2
MEDIUM 4.3 The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
2326ad3a-3b75-4a78-aebc-bb5814e221b4
< 1.2
MEDIUM 4.3 The SEO Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. T… wordfence
231d90b7-6bac-440e-953f-e69ca39ff46e MEDIUM 4.3 The Monetag Official plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
230eb20c-2d0e-4056-b341-4c2db584b70a MEDIUM 4.3 The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil… wordfence
← Prev 1546 1547 1548 1549 1550 1551 1552 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top