πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1564 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
187b072d-6314-4ac1-a924-b14324b2fd8d
< 2.2.2
MEDIUM 4.3 The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access i… wordfence
1878f096-942f-4bc1-ba5f-419ff7ca535c
< 4.5.9
MEDIUM 4.3 The Usercentrics Cookiebot – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode plugin for WordPress is vulne… wordfence
186e4147-4cb4-4337-9c3c-d47589b06b20
< 1.3
MEDIUM 4.3 The Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
186b9f06-e637-4f04-a3c3-13ec8496402c MEDIUM 4.3 The Mediavine Control Panel plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
18530601-a294-448c-a1b2-c3995f9042ac
< 2.0.12
MEDIUM 4.3 The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
184885b0-66cd-433d-bfea-d7e8bbb02731
< 3.9.6
MEDIUM 4.3 The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumb… wordfence
18464483-1d2f-4a4e-a1cc-6c1ddcc2dcf5 MEDIUM 4.3 The 5280 Bootstrap Modal Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
1842ffa7-a9e9-4b35-bec2-e3f9e8622c1c
< 1.3.19
MEDIUM 4.3 The JetBlocks for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … wordfence
180f6542-5f48-4d3c-87f7-1bfcb2d8a0c5 MEDIUM 4.3 The Gmaper for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
180ab1ce-3f5c-4768-9f94-23ed4bc59a4b
< 2.14.2
MEDIUM 4.3 The Zoho Flow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.14.1.… wordfence
18086779-a7db-4550-b44f-c10a5bf974cf MEDIUM 4.3 The Auction Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.… wordfence
17f7c974-492d-4775-b602-bbec36d3bd8f MEDIUM 4.3 The Custom Post Type Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
17f2b07d-82de-4e25-9b17-ef4a1132e6c0
< 3.8.4
MEDIUM 4.3 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
17e8a743-7985-4b28-b854-ac052a834f3a
< 1.1.23
MEDIUM 4.3 The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference i… wordfence
17c7c61d-c110-448e-ad8a-bc1c00393524
< 1.1.3
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
17bc3a9f-2bf9-44e3-81ef-bfa932085da9
< 2.8.8
MEDIUM 4.3 The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… wordfence
17b20df5-4adf-47ce-bddf-2ec0b9499de8
< 4.9.3
MEDIUM 4.3 The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an… wordfence
17ab4800-0afd-4c39-970a-bd8dcc6a8b93
< 6.4.8
MEDIUM 4.3 The Complianz plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in version… wordfence
179751c8-a634-4a2e-be29-46be0aad79c8
< 3.4.0
MEDIUM 4.3 Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an a… wordfence
17792afd-c40c-44cb-844e-86020adfc9eb
< 3.1.4
MEDIUM 4.3 The Vitepos – Point of sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due… wordfence
1777d037-d72d-44a6-946a-a97e20bd2839
< 3.7.42
MEDIUM 4.3 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure… wordfence
17621978-cff5-4e63-bf6e-f1349da74730
< 6.2.1
MEDIUM 4.3 The Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… wordfence
175e08ce-aec2-427a-90e0-f955711d58b2
< 3.9.13
MEDIUM 4.3 The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gu… wordfence
175dd04d-ce06-45a0-8cfe-14498e2f9198
< 3.1.14
MEDIUM 4.3 The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to … wordfence
175cb977-dcba-429f-814c-6de078e23472
< 4.10.32
MEDIUM 4.3 The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa… wordfence
← Prev 1561 1562 1563 1564 1565 1566 1567 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top