πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1567 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
14b9fbd2-206d-49e2-9b53-a7ba459ee518
< 3.10.4
MEDIUM 4.3 The Posti Shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.… wordfence
14b323e6-1a21-419f-83cc-74cf07cbb6d4 MEDIUM 4.3 The Salon Booking Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
14b2fa77-dc51-47b4-913a-9129f95ba766 MEDIUM 4.3 The Soundcloud Is Gold plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… wordfence
14b10f8e-37dd-4a34-87da-c09fdb8e09b3
< 3.0.9
MEDIUM 4.3 The Prodigy Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includ… wordfence
1492440d-c6c8-46c0-bc88-c9e3f9933ad4 MEDIUM 4.3 The Easy Restaurant Table Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
148ca1d5-c20d-40dc-b078-ecd76d4d6c0b MEDIUM 4.3 The Business Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
148794ea-3bc9-4084-bdb9-6ee63a781a39
< 3.4.2
MEDIUM 4.3 The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
147e47f8-c40b-4ae7-8627-b32b36e4d14f MEDIUM 4.3 The Product Category Tree plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
1475f3c4-b1ff-422c-a832-f6261361c240 MEDIUM 4.3 The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and inc… wordfence
146b4d69-70bc-4843-b76c-d91de0cefc9d
< 2.9.0
MEDIUM 4.3 The Asgaros Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8… wordfence
1463cfe6-e158-44b2-a7ae-215e56d33856 MEDIUM 4.3 The Testimonial Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
144d7817-5916-4fbd-8ef6-e4c66c55a119
< 1.4.7
MEDIUM 4.3 The Contact Form Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
144555bc-b92f-4339-a1b2-397dfe6a78de
< 2.8.7
MEDIUM 4.3 The Stock Locations for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
1431dcfe-08b7-40d3-b82b-d0b101873c39
< 2.5.5
MEDIUM 4.3 The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
14250ff2-66e4-48f9-8f73-7f245079134c
< 1.0.2
MEDIUM 4.3 The Popularis Verse theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
1417fad0-51a0-4091-8f7b-4e8925fd71a0
< 4.3.1
MEDIUM 4.3 The AppPresser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.0.… wordfence
141137a4-609f-4ea9-beba-d37b48144c29 MEDIUM 4.3 The WPBlogSyn plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. Th… wordfence
140a6fd3-e446-44ea-94eb-9c8d12f7b7ed
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
1404c675-49b3-48a5-8aac-826c58755b8e
< 1.5.2
MEDIUM 4.3 The SpeedSize Image & Video AI-Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
13fb8d16-2904-4c04-9ea6-5bafdf30f563 MEDIUM 4.3 The Enhanced Search Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
13f87248-cc0b-4351-b79d-6efc5190b021
< 3.3.1
MEDIUM 4.3 The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Obj… wordfence
13d16955-056d-45c5-b0d1-891767e866b2
< 1.4
MEDIUM 4.3 The CMS Tree Page View plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on t… wordfence
13cced58-1546-4afb-949a-f6d0ce8145c1 MEDIUM 4.3 The Contact Form 7 Select Box Editor Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
13c969f3-55d7-4a05-aec8-460bb6faf9da
< 1.15
MEDIUM 4.3 The Admin Menu Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
13c66a8f-b35f-4943-8880-0799b0d150f7
< 1.0.8.2
MEDIUM 4.3 The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to unauthorized acc… wordfence
← Prev 1564 1565 1566 1567 1568 1569 1570 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top