ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1563 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
19b307a8-b01e-484a-b67f-73cbbc66a87b MEDIUM 4.3 The XML Travel Portal Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
19a54519-239c-4b2e-859d-c9aac54165c7
< 5.30
MEDIUM 4.3 The Reviews Widgets for Google & 45+ platforms by Repuso plugin for WordPress is vulnerable to unauthorized access due t… wordfence
198cb3bb-73fe-45ae-b8e0-b7ee8dda9547
< 2.8.8
MEDIUM 4.3 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (… wordfence
198a24e6-af98-42ed-bf58-73b7ec99838b
< 2.05
MEDIUM 4.3 The Portfolio Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
19738a82-8c31-45bb-a869-68e357299eb5
< 5.1.4
MEDIUM 4.3 The Employee Spotlight – Team Member Showcase & Meet the Team Plugin for WordPress is vulnerable to unauthorized track… wordfence
1972c2f5-636e-4891-a0fb-e80207787e43
< 8.71
MEDIUM 4.3 The IdeaPush plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.69. Th… wordfence
196d472b-b268-48f1-8dda-ee6d9e659483
< 3.2.14
MEDIUM 4.3 The BlockSpare — News, Magazine and Blog Addons for (Gutenberg) Block Editor plugin for WordPress is vulnerable to Sen… wordfence
195cc773-b3ea-4619-af2d-b106a9d23a6a
< 6.3.2
MEDIUM 4.3 The Advanced Custom Fields Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
19544e08-fa14-4251-bcc2-e46ebccca075
< 3.12.28
MEDIUM 4.3 The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and exclud… wordfence
1951ad6c-17b5-44ae-85e2-376b99df742e MEDIUM 4.3 The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
194face3-36ac-4137-af9a-0b98f60e3afb
< 1.0.4
MEDIUM 4.3 The Import / Export Customizer Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
19339b9f-8242-44a5-8239-7ef347ffbaad MEDIUM 4.3 The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
19290ae2-0eec-4b95-baa6-44f507a75e0a
< 9.19
MEDIUM 4.3 The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Sensitive Information Exposure… wordfence
192335c4-b244-4308-bd3a-cf96c1461309
< 1.7.13
MEDIUM 4.3 The Multi Step Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
191a74ed-d5f2-4347-9969-10102d1504b8 MEDIUM 4.3 The Önceki Yazı Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
18f48182-eb54-4834-bf39-1bdb1e010a6e
< 3.3.62
MEDIUM 4.3 The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
18f04566-3a63-41f3-aa9b-766304d56499
< 1.1.2
MEDIUM 4.3 The TH Side Cart and Menu Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
18eb8b2a-8e08-4f78-9501-927c025ea574
< 1.6.124
MEDIUM 4.3 The Mesmerize theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.120.… wordfence
18e24a2e-cbc6-4285-b846-bea513b6ff69
< 1.4.11
MEDIUM 4.3 The TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds plugin for Word… wordfence
18d615ff-f617-48fb-bf9c-0f6faff18c64 MEDIUM 4.3 The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Cross-Site Request Forger… wordfence
18c64296-9f84-426d-a6a0-209faf56c0b9
< 24.07.05
MEDIUM 4.3 The Docket Cache – Object Cache Accelerator plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
18bcd2ad-1989-4e2b-b82e-fddc4201c5a6 MEDIUM 4.3 The Simple Crypto Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
18b77c9b-6614-4a3f-a003-54567d9c4408 MEDIUM 4.3 The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
18a9953c-e3a0-46ee-9a53-984c411ce408 MEDIUM 4.3 The DX-Watermark plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… wordfence
1891a8b7-3c70-4be1-80e1-fdc787261cbd MEDIUM 4.3 The Homlisti theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
← Prev 1560 1561 1562 1563 1564 1565 1566 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top