πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1551 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
21d1c8c9-dcfc-4368-acc2-67e4e3605f16
< 12.0.1
MEDIUM 4.3 The JNews Paywall plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 12.0.1 (exclusi… wordfence
21ca7d14-a6b1-4d02-81c7-bfc5623c4818
< 5.9.5.2
MEDIUM 4.3 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due … wordfence
21a7bb17-aaa6-49c8-a433-483fac4d555f
< 3.13.8
MEDIUM 4.3 The Rencontre – Dating Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
218e4ed5-661b-49e1-8b23-457a93fd53fa
< 4.7.1
MEDIUM 4.3 The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… wordfence
218d0d28-16db-4d9c-b643-6cc2edfc74e2 MEDIUM 4.3 The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
218c91f5-8328-4ab2-a52a-66c32934a130
< 1.6.3
MEDIUM 4.3 The UPI QR Code Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
217b1213-de46-4c1d-baea-41a859bfcc60
< 2.9.11
MEDIUM 4.3 The WP User Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
2178b39c-5341-4f53-82be-668b400d7f25
< 1.0.14
MEDIUM 4.3 The Userback plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… wordfence
21616ffc-44aa-45ca-8304-cb9d4ab5621d
< 1.0.18
MEDIUM 4.3 The TuriTop Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
2160cf45-e1a1-475f-9de9-8ae7345a9b19 MEDIUM 4.3 The Bulk Featured Image plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
215d5d9e-dabb-462d-8c51-952f8c497b78
< 4.2.5.8
MEDIUM 4.3 The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi… wordfence
215be163-f362-4bda-b81a-65ec955968a2 MEDIUM 4.3 The BTEV plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. T… wordfence
2136cad8-6b0b-4458-a357-6e98f1ac3e0b
< 2.6.12
MEDIUM 4.3 The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… wordfence
2134bfd6-db71-4117-87a7-6ad4107d3b39 MEDIUM 4.3 The Don Peppe theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
212e5d55-5b28-41d6-86a0-d247d6c81f0d MEDIUM 4.3 The Redirect countdown plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
212dd123-42d4-4dd2-a2e2-bf0c43e805bf
< 2.1.3
MEDIUM 4.3 The Forget About Shortcode Buttons plugin for WordPress is vulnerable to unauthorized plugin settings update due to a mi… wordfence
212b7da7-bd3e-42df-8b50-a3eb472cf440
< 1.8.5
MEDIUM 4.3 The Zendesk Support for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
2123a3cc-08f1-4e30-ac61-275d45cd1227
< 1.8.0
MEDIUM 4.3 The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
2121d9fa-bab4-489d-89bc-07a8660bc3d1
< 4.5.1
MEDIUM 4.3 The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization byp… wordfence
211b8b76-d770-443b-ba95-84b30adc5d48
< 1.3.326
MEDIUM 4.3 The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Cr… wordfence
20f0e9ae-786b-4ba8-a6d5-92bf31ebc2c7
< 2.8.17
MEDIUM 4.3 The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in v… wordfence
20d5ff9e-9920-47c7-aa8d-e4f9f1646080
< 1.6.2
MEDIUM 4.3 The ARForms Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
20b3b64f-e6d7-4ccd-98f3-417390bd2393 MEDIUM 4.3 The OpenAI Tools for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
209341fa-6761-4bc4-a921-afa98495a087
< 1.6.6
MEDIUM 4.3 The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modificat… wordfence
20910787-b99d-475e-acc9-cc2bb669aa56
< 2.5.3
MEDIUM 4.3 The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
← Prev 1548 1549 1550 1551 1552 1553 1554 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top