πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1566 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
15db421c-3744-492a-830d-0f12bafdd6a8 MEDIUM 4.3 The History Timeline plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
15d9c743-5700-482a-a6bc-ecf541ea9e7d
< 1.1.0
MEDIUM 4.3 The leads5050-visitor-insights plugin for WordPress is vulnerable to authorization bypass due to a missing capability ch… wordfence
15d479e7-f0b8-4175-84b0-cd611b73233a
< 2.8.9
MEDIUM 4.3 The Portfolio – WordPress Portfolio Plugin plugin is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
15ccc672-f692-4d6b-abe6-15f6ea42902b
< 1.7.0
MEDIUM 4.3 The Robin image optimizer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability … wordfence
15cb0e8a-907c-4fc0-9ea0-bbce956723a1
< 2.4.17
MEDIUM 4.3 The Kali Forms β€” Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Insecure Direct Object Ref… wordfence
15cad3f3-5a23-427f-8dd2-8edf38245fe0
< 1.12.21
MEDIUM 4.3 The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin f… wordfence
15c2316f-99ef-42fd-85ca-e905e711436a
< 0.5.9
MEDIUM 4.3 The Off-Canvas Sidebars & Menus (Slidebars) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
15b7008f-07fc-4f8a-b214-8ac0c4cf6d99
< 5.5
MEDIUM 4.3 The Animated Rotating Words (Interchanging Random Words in a Sentence) plugin for WordPress is vulnerable to Cross-Site … wordfence
15903e57-75e1-428c-b042-bf4c1c521db9 MEDIUM 4.3 The Modern Polls plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
157c5aff-8a3e-4ca3-8ac7-e054df6db912 MEDIUM 4.3 The Lottier for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
157a0e97-5600-4736-846c-146668d27710 MEDIUM 4.3 The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Cross-Site Reque… wordfence
155f494b-be25-4269-9d3b-379309619bbe
< 1.4.8
MEDIUM 4.3 The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Informatio… wordfence
155e43f2-d46f-413f-bedd-7ab8905c1c35
< 4.0.0
MEDIUM 4.3 An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. A user can perform an insecure direct o… wordfence
1559fb43-cc5e-4dd2-80d8-06a137c7276d
< 2.3.1
MEDIUM 4.3 The Wp Ultimate Review plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
154a838c-f8bb-4568-b066-a78264c75eea
< 1.4.6
MEDIUM 4.3 Several themes for WordPress are vulnerable to unauthorized modification of data due to a missing capability check on th… wordfence
1534f67d-cf3f-4185-9aa6-01ae5dee4f26
< 1.8.16
MEDIUM 4.3 The Photo Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on… wordfence
15177d1b-ef48-49e3-9bd9-34262ed2c134 MEDIUM 4.3 The WP-Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including … wordfence
150ac796-d77b-4915-8bbf-9f9b54be8eaf
< 2.3.1
MEDIUM 4.3 The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insec… wordfence
14e832ec-7181-44d9-8d26-2f77e6111763
< 3.2.4
MEDIUM 4.3 The Top 10 – Popular posts plugin for WordPress is vulnerable to unauthorized cache deletion due to a missing capabili… wordfence
14e6e06c-edc0-44ef-ba07-50fcfc4fd7b1
< 2.0.3
MEDIUM 4.3 The WooCommerce Pre-Orders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
14e00e65-32ce-4bd3-b118-5f92af6aa979
< 4.2.1.1
MEDIUM 4.3 The WPVulnerability plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
14d71220-be60-498d-92ca-055f1c237060 MEDIUM 4.3 The Just Custom Fields plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capab… wordfence
14d3b859-def9-4949-95bc-f25067674811
< 2.9.33
MEDIUM 4.3 The Netgsm plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
14c5fd0c-0872-4b05-b28b-11353e9276d0
< 2.5.0
MEDIUM 4.3 The Comments Import & Export plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
14bf654e-c4f1-4267-811e-6d796c14834a
< 1.2.2
MEDIUM 4.3 The Floating Action Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
← Prev 1563 1564 1565 1566 1567 1568 1569 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top