🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1552 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2089b54c-9a34-4701-84bf-56b64e51982b
< 1.6.2
MEDIUM 4.3 The ValidateCertify Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
2077bd81-52bd-4aa7-85f6-9abb02aec65b
< 4.0.1
MEDIUM 4.3 The JCH Optimize plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability check… wordfence
206c386c-15c2-4701-a011-e54d0cb3596c MEDIUM 4.3 The Grand Portfolio theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.… wordfence
2061a442-eccd-4a57-a5c5-a432fcea8394
< 2022.9.29
MEDIUM 4.3 The Administrator Z plugin for WordPress uses Advanced Custom Fields which has a file upload vulnerability in versions u… wordfence
205a6972-b49f-4b6d-b0de-7a047d5ee496
< 2.2.5
MEDIUM 4.3 The WP Upload Restriction plugin for WordPress is vulnerable to authorization bypass due to a missing capability check o… wordfence
204107bc-721c-46a9-a8c3-102240f66fc2
< 2026.05.10
MEDIUM 4.3 The Administrator Z plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and excludin… wordfence
20151f80-c25f-482e-a2b0-34607dba9d1e
< 6.0.1
MEDIUM 4.3 The Floating Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6… wordfence
200fbfc1-df21-43b0-8eb1-b2ba0cc0c0df
< 1.2.92
MEDIUM 4.3 The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capabili… wordfence
200b3446-6107-434b-b46d-2078461f3f94
< 1.3.0
MEDIUM 4.3 The ImagePress – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
2009a0d7-ce42-46b5-986d-33e3d06a513d
< 1.127.0
MEDIUM 4.3 The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
2008df3e-29d2-4d64-b850-c83c2a6a9996
< 2.2.5
MEDIUM 4.3 The Mark Posts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
1ff5889e-b9fd-494f-b25d-78e85e94d34c
< 1.1.25.2
MEDIUM 4.3 The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24… wordfence
1fe73b99-f113-4514-ae13-e22f897608b2
< 3.2.4
MEDIUM 4.3 The New User Approve plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
1fe3e2bf-9fbd-4534-8389-8383cb2370a8
< 1.2.3
MEDIUM 4.3 The Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to … wordfence
1fe2ea48-6764-4b1c-a811-423fac23f98a
< 2.9.6
MEDIUM 4.3 The Points and Rewards for WooCommerce – Create Loyalty Programs, Reward Customer Purchases, User Badges, Gamification… wordfence
1fd84e08-abc2-4655-999c-6dcdaa7f372c MEDIUM 4.3 The Casengo Live Chat Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
1fcbe3d1-449c-4135-bbf5-9ea9236e5328
< 2.8.7
MEDIUM 4.3 The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request… wordfence
1fc58078-7520-4ee7-b5a1-d6a362ac1860
< 2.1.5
MEDIUM 4.3 The DeepL Pro API translation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
1fc0f287-8f39-4580-b58e-c308a603ba32
< 1.2.6
MEDIUM 4.3 The WP Gravity Forms HubSpot plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1… wordfence
1fa45fa7-b1da-42f0-945b-2a6b0db5ba91 MEDIUM 4.3 The Enable/Disable Auto Login when Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
1f9d4d86-9d5f-4888-9cc4-d55c117ae4ea
< 2.4.0
MEDIUM 4.3 The Different Menu in Different Pages – Control Menu Visibility (All in One) plugin for WordPress is vulnerable to una… wordfence
1f96a0f3-8ebf-40b7-8498-157373e95b22
< 7.1.0.38
MEDIUM 4.3 The Xagio SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
1f7aa23c-ffa7-481b-8481-a36c7ed599d8
< 5.2.6
MEDIUM 4.3 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site R… wordfence
1f66cdcf-cbe5-43e0-ad18-c2b9c4491ed4
< 2.4.2
MEDIUM 4.3 The Music Player for Elementor – Audio Player & Podcast Player plugin for WordPress is vulnerable to unauthorized modi… wordfence
1f533cf9-bec8-48a8-87e3-99117a9948f1 MEDIUM 4.3 The افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری plugin for … wordfence
← Prev 1549 1550 1551 1552 1553 1554 1555 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top