πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1550 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
230b3f2f-44cf-46eb-8e6a-3c52f2ea2fb9
< 1.5.4
MEDIUM 4.3 The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … wordfence
22f6a369-7068-4df8-9c6c-f20cceb0c39b
< 1.3.1
MEDIUM 4.3 The Shoppable Images (Lookbook) for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
22e0060d-7852-4326-98bc-1c49bebe6205
< 2.6.0
MEDIUM 4.3 The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missi… wordfence
22defe19-28ac-43b3-814d-5a2038380adb
< 6.3
MEDIUM 4.3 The Page-list plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.2. Thi… wordfence
22b742d7-e9fe-48ea-ae7f-579bd3c32c44
< 9.5
MEDIUM 4.3 The Easy Social Share Buttons plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
228d63a5-5053-4692-9801-4860325da153
< 2.3.1
MEDIUM 4.3 The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Miss… wordfence
22842e7a-9cbb-4b29-b4cb-7d9b8d6b7b1a
< 7.5.1
MEDIUM 4.3 The LifterLMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.5.0. … wordfence
2283210d-d3b6-433f-ab17-5b29d7752aa6
< 4.5.1
MEDIUM 4.3 The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to Cross-Site Reques… wordfence
227d81e8-7380-4bc8-8127-046ff87bb4b1
< 2.7.24
MEDIUM 4.3 The Brizy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
227c8700-6e53-4f06-9620-5dde2ffc4fde MEDIUM 4.3 The Heateor Social Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
2277e9d3-9589-42a7-9649-50afbf20a94a
< 1.5.58
MEDIUM 4.3 The Query Wrangler plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
2275f49d-2b31-4e24-aa3f-16f5febd2738
< 1.10.37
MEDIUM 4.3 The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
2270b66f-b07c-44ce-b161-7b2123f8c21e
< 1.120.47
MEDIUM 4.3 The PeachPay β€” Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugi… wordfence
225916f2-b582-47e6-a603-54e5e28fda41 MEDIUM 4.3 The AI Tools – Chatbot, ChatGPT, Content Generator, Image Generator, Artificial Intelligence GPT plugin for WordPress … wordfence
2253cb38-3688-4e4d-afd1-582c8743c89a
< 2.73
MEDIUM 4.3 The 301 Redirects - Easy Redirect Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
22445eb5-b37b-4bdb-95cc-d07b8630cd84
< 3.0.0
MEDIUM 4.3 The Rollbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.1… wordfence
223a6c35-712a-458c-8708-6981c9041fe1
< 2.4.3
MEDIUM 4.3 The Woocommerce Category Banner Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
22283650-36bf-43e5-a57e-a91025fb2af7
< 5.7.27
MEDIUM 4.3 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… wordfence
2227cde8-5ed6-44dd-80cc-2a85aaa172c1
< 1.2.0.2
MEDIUM 4.3 The WPCS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.0.1. Thi… wordfence
22172d16-bcde-4516-bce0-222fbb7a76f7
< 2.0.8
MEDIUM 4.3 The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and i… wordfence
2216d82c-29ae-4355-8118-6ebc49726c12
< 2.0.6
MEDIUM 4.3 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Obje… wordfence
22143fe3-e599-4b44-99c0-ba66d88ff5d6
< 3.0.0
MEDIUM 4.3 The Image Alt Text plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability … wordfence
21f710ee-5040-4916-9fde-efc6d3b90943
< 5.2.7
MEDIUM 4.3 The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
21e49adb-01a7-41d9-bb51-bac60d49e293
< 1.6.11
MEDIUM 4.3 The Spotlight Social Media Feeds plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
21dae604-4986-4ceb-ba58-88634b4bfe8c
< 2.0.0
MEDIUM 4.3 The Parallax Section Block – Add Parallax Scrolling Effects to Sections. plugin for WordPress is vulnerable to unautho… wordfence
← Prev 1547 1548 1549 1550 1551 1552 1553 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top