πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1558 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1e93ce8c-5489-48e9-85a1-00ef897d0d74
< 2.6.9
MEDIUM 4.3 The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
1e8f0ef8-4916-4b62-a062-f169ba15448e
< 3.12.28
MEDIUM 4.3 The Easy Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and excl… wordfence
1e7bc0b1-a4ba-42f6-b6c9-0dcf2f8975ad
< 8.6.12
MEDIUM 4.3 The MapSVG plugin for WordPress is vulnerable to Path Traversal in all versions up to 8.6.12 (exclusive). This makes it … wordfence
1e72fd72-9771-442c-86d9-5dcc21df6c09
< 1.3.4
MEDIUM 4.3 The Cyr to Lat Reloaded – Transliteration of Links and File Names plugin for WordPress is vulnerable to unauthorized a… wordfence
1e716cf9-198c-4a32-883d-3f90dd399aee
< 2.3.0
MEDIUM 4.3 The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data… wordfence
1e636fdd-6081-45f0-8e5d-71991ca7ed1a MEDIUM 4.3 The Simple Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
1e5a9cf2-2f1a-418c-99db-0c96077710eb
< 1.0.8
MEDIUM 4.3 The DEPART plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
1e567aec-07e5-494a-936d-93b40d3e3043
< 1.1.3
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability ch… wordfence
1e5381fe-940b-404e-b2f2-1fd1c4ee5d78
< 2.3.9
MEDIUM 4.3 The Flexible Elementor Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
1e4e8960-b0c1-4dbb-ba97-e45b88fb06c0
< 1.1.6
MEDIUM 4.3 The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulne… wordfence
1e48639e-01bb-4980-be6f-bcea3dd16fc5
< 2.0.5
MEDIUM 4.3 The Download Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
1e3ba5cf-1c70-4b6e-ab76-0103dad44732
< 3.0.0
MEDIUM 4.3 The GA4WP: Google Analytics for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
1e2c937c-1ff8-4bcc-913b-83bade37d754
< 2.1.9
MEDIUM 4.3 The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu… wordfence
1e280530-74de-42d2-bffe-3db24f72636d
< 6.2.2
MEDIUM 4.3 The Herd Effects plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2.… wordfence
1e1db52a-3966-4e04-b0ed-08bda9ba1ff6
< 1.27
MEDIUM 4.3 The Republish Old Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
1e19ef28-5223-4ced-b9f2-3c5aa5d91264 MEDIUM 4.3 The Conditional Cart Messages for WooCommerce – YourPlugins.com plugin for WordPress is vulnerable to Cross-Site R… wordfence
1e07e570-e4c0-472c-b582-40a87a6507bf
< 6.6.3
MEDIUM 4.3 The WP SMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.2. Thi… wordfence
1dff665d-df42-4b67-bea2-4d6273714d8d
< 3.0.17
MEDIUM 4.3 The Animator – Scroll Triggered Animations plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
1df31843-0af7-486c-b0aa-4eaf72a7e70f
< 2.25.26
MEDIUM 4.3 The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
1de8da4c-dee7-4d59-a475-a969008aa0d4
< 1.9.9
MEDIUM 4.3 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure… wordfence
1ddfd5d9-a7e4-42a8-8419-9a35b4781d3c
< 3.8.6
MEDIUM 4.3 The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to authorization bypass due to incorrectly defined… wordfence
1ddcd2eb-fd7a-48b7-b9ea-3632d49e9734
< 2.9.35
MEDIUM 4.3 The MasterStudy LMS WordPress Plugin is vulnerable to unauthorized access of data due to a missing capability check on … wordfence
1dd4e39a-9b2f-4728-b026-2dee60257c46
< 3.2
MEDIUM 4.3 The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
1db1c415-7c57-47bb-82d9-44168259ae1a
< 2.4.1
MEDIUM 4.3 The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
1da1d851-10ba-45e8-a486-03ac409075a4 MEDIUM 4.3 The WPBookit plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… wordfence
← Prev 1555 1556 1557 1558 1559 1560 1561 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top