🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1565 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
17453fa5-af14-477b-9b3d-b245511ad8ce
< 6.4.2.6
MEDIUM 4.3 The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
172d4a39-a46f-4ffd-a4cc-3f53c78a3c4e MEDIUM 4.3 The WP Ultimate Tours Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
1725c7f3-2fac-4714-a63e-6c43694483fc
< 4.0.5
MEDIUM 4.3 The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorize… wordfence
17215b12-a134-40e1-b431-22372dabd18f
< 8.8.4
MEDIUM 4.3 The Simple Link Directory plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
1707b5ba-56ce-46e5-97fc-918005f5ae49
< 1.3.5
MEDIUM 4.3 The Ultimate WP Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
17031e21-e697-4e01-8848-c3957f5dac7f
< 1.0.5
MEDIUM 4.3 The Real Estate Directory themes for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
16f9ca70-50fe-4fab-8a58-57af795dc000 MEDIUM 4.3 The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
16dc1927-2171-4234-805b-6e4eed99fa90
< 1.7.28
MEDIUM 4.3 The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
16c7813c-7814-43f1-b051-e7e8690de21e
< 4.3.1
MEDIUM 4.3 The AppPresser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.0.… wordfence
1690631b-0e5d-45d1-9db6-6ac426874762
< 1.1.11
MEDIUM 4.3 The HelloAsso plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
1666170c-6489-4fbb-8356-f1a7790d74d6
< 8.2.1
MEDIUM 4.3 The CartBounty – Save and recover abandoned carts for WooCommerce plugin for WordPress is vulnerable to Cross-Site Req… wordfence
164ec659-e1a6-4267-b6e9-4e37a402e503
< 1.7.7
MEDIUM 4.3 The Slideshow Gallery LITE plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
164e9694-3cfd-4cac-8376-deabb1738abf
< 2.6.8
MEDIUM 4.3 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
164a1e09-e967-450c-8938-84c18ebf267d
< 5.4.12
MEDIUM 4.3 The Element Pack Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
16429860-d2a6-4b08-b2da-012ec2d4e2c3
< 1.4.9
MEDIUM 4.3 The Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons plugin for WordPr… wordfence
16391236-10c8-495e-a0a9-431d1a5aad3f MEDIUM 4.3 The Creative Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
163328e9-2918-4bc0-8bbc-90d7e992754d
< 3.8.4
MEDIUM 4.3 The WooCommerce Ship to Multiple Addresses plugin for WordPress is vulnerable to insecure direct object reference in ver… wordfence
16308adf-b5d0-4519-8b1e-3d200003e8be
< 7.6.34
MEDIUM 4.3 The Comments – wpDiscuz plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
161d92e3-d255-4967-9449-be263a46bec8
< 10.14.12
MEDIUM 4.3 The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposu… wordfence
16187b39-9b3a-4b1c-806c-37b62483a719
< 3.1.0
MEDIUM 4.3 The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin… wordfence
16073ffd-d95a-4e1e-9593-c2e5ae57f303 MEDIUM 4.3 The CB (legacy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0… wordfence
16041d22-51ff-4fa4-99fb-20a60b557634
< 2.10.0
MEDIUM 4.3 The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modi… wordfence
1600466e-ad45-4dc7-916b-6c97301d2b03
< 28.0
MEDIUM 4.3 The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7… wordfence
15f62766-d843-4fdb-a77e-fd7738c1a50c MEDIUM 4.3 The Masker for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
15f39c64-2586-4fd0-97d2-19dd8ad04a8f
< 1.14.0
MEDIUM 4.3 The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… wordfence
← Prev 1562 1563 1564 1565 1566 1567 1568 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top