🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1555 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1d3e476d-0885-4e8c-a682-bd64d9f13b53
< 1.7.1
MEDIUM 4.3 The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin plugin for WordPress is vulnerable to unautho… wordfence
1d3cc32b-e415-4350-811a-c799a6ec24b6
< 3.9.14
MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Expos… wordfence
1d387d8e-198c-476a-9688-6842a871571e
< 1.2.9
MEDIUM 4.3 The Hash Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.8. … wordfence
1d12f5c5-2f81-4cf5-9ba9-e0949fc5bb48 MEDIUM 4.3 The Społecznościowa 6 PL 2013 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
1d0a40f8-4c31-447d-ac28-73cfe7a07687
< 4.7
MEDIUM 4.3 The EventON PRO - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
1cee249d-0a0e-4675-9e35-3a177a3b74a2 MEDIUM 4.3 The Custom Skins Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… wordfence
1cec03d3-0e80-4025-b782-1ce9c3237569
< 3.7.1
MEDIUM 4.3 The Contact Us Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… wordfence
1cebb69a-3096-48fa-903c-b4eff62eec6d MEDIUM 4.3 The Bard theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in ver… wordfence
1ce7c895-e94c-46bd-9de1-f5fde29c3475
< 2.0.3
MEDIUM 4.3 The Cool Timeline (Horizontal & Vertical Timeline) plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
1cdadc61-8a8d-446a-8f7e-9fecd7d687b1
< 1.0.21
MEDIUM 4.3 The Poptics – Popup Builder, Email Opt-ins, Exit-Intent & WooCommerce Popups Sales plugin for WordPress is vulnerable … wordfence
1cd5acfc-0338-4958-8f46-3d7b14ef0e14
< 1.4.1
MEDIUM 4.3 The Media Library Downloader plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
1ccc8b30-1bdf-4335-85a9-79c6f9a88afc
< 1.0.7
MEDIUM 4.3 The Sweet Energy Efficiency plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data du… wordfence
1cc64898-8724-4ba5-9260-02c647812cc8 MEDIUM 4.3 The BD Courier Order Ratio Checker plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
1cb265d8-eb18-42ee-9141-2fe81c0c4585 MEDIUM 4.3 The WP Google Tag Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
1cb1d8a3-91dd-419e-bc4e-57842afeb7b1
< 1.3.70
MEDIUM 4.3 The Appointment Booking Calendar plugin for WordPress is vulnerable to authorization bypass due to a missing capability … wordfence
1c8e615a-a1fc-428d-93bc-27c5d6d758eb
< 3.11.0
MEDIUM 4.3 The WooCommerce Payment Gateway – Paysera plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
1c8c1fec-0e87-46f7-83c5-8f9e9aa97b4f
< 1.4.7
MEDIUM 4.3 The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Th… wordfence
1c85e5e0-d8ee-46d3-99b1-df6c6744f020
< 3.1.2.1
MEDIUM 4.3 Multiple plugins by Crocoblock for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is d… wordfence
1c8034ff-cf36-498f-9efc-a4e6bbb92b2c
< 1.1.3
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
1c7c74cf-a109-4f77-a740-5a43ccd4e96a
< 1.0.7.5
MEDIUM 4.3 The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
1c78009f-c422-408b-a604-1bab4474debd
< 1.5.4
MEDIUM 4.3 The Email marketing for WordPress by GetResponse Official plugin for WordPress is vulnerable to unauthorized access due … wordfence
1c7504e5-26a2-4387-8b79-43d6cf6fd0dc MEDIUM 4.3 The AweBooking – Hotel Booking System plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… wordfence
1c74e434-460f-4ba7-a105-8a8ce766fc2d MEDIUM 4.3 The Parallax Scrolling Enllax.js plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
1c6d5a66-0eec-4a73-ad78-2b66a688c67a MEDIUM 4.3 The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
1c649083-d311-42ce-83be-9aca5933ed47
< 2.4.8
MEDIUM 4.3 The WP Prayer II plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
← Prev 1552 1553 1554 1555 1556 1557 1558 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top