πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1561 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1baf7c7e-b5e9-40b5-9c96-abe6ebcf2b2a
< 1.7.9
MEDIUM 4.3 The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated… wordfence
1ba7b675-54d6-4f0e-b60f-1c7fa6ff24ea
< 3.2.1
MEDIUM 4.3 The WordPress Mega Menu – QuadMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
1ba56d68-e104-4a79-b5b4-627f9617043b
< 1.3.35
MEDIUM 4.3 The CP Contact Form with Paypal plugin for WordPress is vulnerable to missing authorization on the 'cpcfwpp_feedback' fu… wordfence
1ba33c84-5198-4c77-8995-d0a315d68990
< 1.7.13
MEDIUM 4.3 The 360 Javascript Viewer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
1b9ed184-814d-46cb-979c-908bc9359fae
< 5.0.7
MEDIUM 4.3 The Swift SMTP (formerly Welcome Email Editor) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… wordfence
1b9103b9-a33d-4838-9454-70fa5277c5a0
< 1.0.36
MEDIUM 4.3 The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
1b8d88e4-a9dc-4740-b836-99f730beefcb
< 3.9.0
MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Expos… wordfence
1b82ce74-11ac-4719-961d-a16717ce023b
< 2.3.4
MEDIUM 4.3 The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin f… wordfence
1b5de554-1d2f-4932-9f93-1333b07edeba
< 1.2.8
MEDIUM 4.3 The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2… wordfence
1b3bd31f-0f5a-4b4a-811b-5482db866bd5 MEDIUM 4.3 The AutoCatSet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.… wordfence
1b3b8a6c-1c84-4abe-ad4a-02302b04987b
< 1.2.0
MEDIUM 4.3 The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable … wordfence
1b377236-bb56-4d31-837a-c5064d46a6c6 MEDIUM 4.3 The WhitePage plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.5. … wordfence
1b3610f3-d589-4a45-9f80-6b66205de093
< 5.13.1
MEDIUM 4.3 The Meta Box plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to 5.13.1 due to miss… wordfence
1b2b49af-1bed-4c81-95c2-f8b80c06a829
< 3.4
MEDIUM 4.3 The Posterity theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3. Thi… wordfence
1b2ad299-03b1-4b9e-a241-d2ad2d85c3ac
< 4.1121
MEDIUM 4.3 The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct… wordfence
1b25df18-dd9a-4b24-8187-283d5f3f334e
< 3.10.2
MEDIUM 4.3 The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi… wordfence
1b0e8594-785c-4e15-b037-3834a01da793
< 1.19.1
MEDIUM 4.3 The Email Marketing for WooCommerce by Omnisend plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
1b01991c-de16-43c4-bb11-c8730230ce51 MEDIUM 4.3 The Debug Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th… wordfence
1aed51a2-9fd4-43bb-b72d-ae8e51ee6e87
< 3.9.7
MEDIUM 4.3 The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the m… wordfence
1add8693-20df-431e-ad3b-b23322f1fa03
< 1.0.16
MEDIUM 4.3 The Userback plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the … wordfence
1ad5d2b2-fca8-46bb-8a03-02be07f2a800
< 1.2.8
MEDIUM 4.3 The Bard Extra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
1ad366f1-2369-4fb2-aeda-301c85cf6801 MEDIUM 4.3 The Layer Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.… wordfence
1ab56d29-7e35-4bc3-812e-d82890f60c8e
< 2.2
MEDIUM 4.3 The Custom Twitter Feeds (Tweets Widget) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
1aa0fd9d-6c9f-4110-92a0-064fa4b9b589
< 1.30
MEDIUM 4.3 The WP Open Street Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
1a7de110-e581-4cf7-9f2f-edb4a305dff5
< 1.9.14
MEDIUM 4.3 The Envo Extra plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
← Prev 1558 1559 1560 1561 1562 1563 1564 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top