πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1560 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1c8e615a-a1fc-428d-93bc-27c5d6d758eb
< 3.11.0
MEDIUM 4.3 The WooCommerce Payment Gateway – Paysera plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
1c8c1fec-0e87-46f7-83c5-8f9e9aa97b4f
< 1.4.7
MEDIUM 4.3 The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Th… wordfence
1c85e5e0-d8ee-46d3-99b1-df6c6744f020
< 3.1.2.1
MEDIUM 4.3 Multiple plugins by Crocoblock for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is d… wordfence
1c8034ff-cf36-498f-9efc-a4e6bbb92b2c
< 1.1.3
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
1c7c74cf-a109-4f77-a740-5a43ccd4e96a
< 1.0.7.5
MEDIUM 4.3 The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
1c78009f-c422-408b-a604-1bab4474debd
< 1.5.4
MEDIUM 4.3 The Email marketing for WordPress by GetResponse Official plugin for WordPress is vulnerable to unauthorized access due … wordfence
1c7504e5-26a2-4387-8b79-43d6cf6fd0dc MEDIUM 4.3 The AweBooking – Hotel Booking System plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… wordfence
1c74e434-460f-4ba7-a105-8a8ce766fc2d MEDIUM 4.3 The Parallax Scrolling Enllax.js plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
1c6d5a66-0eec-4a73-ad78-2b66a688c67a MEDIUM 4.3 The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
1c649083-d311-42ce-83be-9aca5933ed47
< 2.4.8
MEDIUM 4.3 The WP Prayer II plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
1c61b3a7-25a9-4890-a294-378883ebe11d
< 1.10.32
MEDIUM 4.3 The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
1c51a3f8-dee1-4744-8353-864312c89021
< 2.2.1
MEDIUM 4.3 The WP 2FA plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the login_for… wordfence
1c4b3c9a-ed3e-460b-ac35-dd2c91b30cd8
< 5.1.11
MEDIUM 4.3 The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
1c3a29ec-16f0-4fad-b188-7a683d123bb8
< 4.0.3
MEDIUM 4.3 The SureCart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
1c24f881-52bc-4210-9037-bcdd1e4aa895
< 1.4.0
MEDIUM 4.3 The Best Restaurant Menu by PriceListo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
1c22717f-494e-4f62-9691-ee5a3366a487
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of settings due to a missing ca… wordfence
1c1e1c18-fecd-45a9-a515-11073c9f1aec
< 3.7.1.1
MEDIUM 4.3 The JetEngine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
1c08c309-af52-4aed-8cc3-b93488f3396f
< 1.7.1
MEDIUM 4.3 The Lemmony theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.7.1. This is due to miss… wordfence
1bfb5d34-738d-4842-be93-9668fceb3334
< 2.8.2
MEDIUM 4.3 The Social Media & Share Icons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … wordfence
1bf798b5-2a5c-42d9-a4b3-d3ed056e1fdb
< 2.7.2.3
MEDIUM 4.3 The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
1bea21d5-da96-48fd-89bb-57aea88af793 MEDIUM 4.3 The Simple XML Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
1be686d3-16b1-4ec7-b304-848ca4d7162c
< 3.3.0
MEDIUM 4.3 The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … wordfence
1bd8b315-97a9-40f4-99cb-76f347a5c1e9
< 12.1.2
MEDIUM 4.3 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to unauthorized access due to a … wordfence
1bd308a4-7157-4bc6-a55b-c6a4a62510a9
< 2.1.3
MEDIUM 4.3 The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in… wordfence
1bb55b22-a0d0-424f-8e4f-57d3f239c149
< 1.7.2
MEDIUM 4.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a mi… wordfence
← Prev 1557 1558 1559 1560 1561 1562 1563 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top