πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1568 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
13ba9474-b1ca-4ba4-ad94-88f7795a4c3c MEDIUM 4.3 The CM On Demand Search And Replace plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
13b63844-0ff8-47d3-beef-990a835fdb1c
< 1.2.64
MEDIUM 4.3 The ApusListing theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.63… wordfence
13aa1288-257a-417e-aad8-86075c9b9abe
< 1.79.262
MEDIUM 4.3 The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to unauthorized access due t… wordfence
13a0dd72-1124-4b5d-9bad-fe4fea8e3e68
< 8.2.8
MEDIUM 4.3 The WP VR plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.7. This… wordfence
13981d82-5e27-4cde-8bb7-2ab6155741e3
< 1.2.7
MEDIUM 4.3 The Printus – Automatic Printing Plugin for WooCommerce – Print WooCommerce Orders, PDF Invoices, Packaging Slips & … wordfence
138c636b-27fb-4d76-b01c-60a10749913d MEDIUM 4.3 The Smart Maintenance Mode plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
137ca3b1-703f-4032-8574-02401f4d2e22
< 5.1.18
MEDIUM 4.3 The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
13791cb9-280e-4a48-aa52-85127d6ac0a1 MEDIUM 4.3 The Flatsome theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
137623ec-1e40-4b66-a273-706b630580fe
< 1.5.5
MEDIUM 4.3 The Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including,… wordfence
137327c8-01cb-4074-9424-89d826a9586e
< 10.0.5
MEDIUM 4.3 The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… wordfence
13648a6d-481d-4eb4-82c8-30476454793e
< 5.4.4
MEDIUM 4.3 The Classified Listing plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
1359945a-cf4e-4883-830b-53a3fcd40e56
< 5.0.5
MEDIUM 4.3 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for Word… wordfence
1355bc94-7110-4d61-855e-78889e58dcad MEDIUM 4.3 The WordPress Photo Gallery – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… wordfence
134a3615-a9fa-48b5-8cd1-4c3fb24a777a
< 5.7.9
MEDIUM 4.3 The ProfileGrid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.7.… wordfence
134130a9-4750-4a63-88a0-60d4285acb77 MEDIUM 4.3 The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
130637ce-d70a-4831-8b88-a2a6e8a95c42
< 1.0.263
MEDIUM 4.3 The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
13046019-f390-48ae-bf08-53293c41f178 MEDIUM 4.3 The NOO Timetable plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1… wordfence
13033a3c-f020-4821-a7ad-bfcfca407df0
< 2.0.4
MEDIUM 4.3 The Ultimate Member plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions prior to version … wordfence
12ecf3d5-1457-405a-8856-517c7d2f2db1
< 3.0.18
MEDIUM 4.3 The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
12e64de4-d50f-44df-b150-d23ec9f3a0d5
< 2.6.5
MEDIUM 4.3 The Namaste! LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
12c7661c-0700-4370-9272-d8a19b17006e
< 3.4
MEDIUM 4.3 The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin… wordfence
12c56bf6-ce9b-4c4b-ad7d-0fa54ad221f2
< 1.2.4
MEDIUM 4.3 The SmartFix theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
12bcc338-9e16-410f-bf3b-3756bc9b7024 MEDIUM 4.3 The Comment Info Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
12b81441-d22c-4211-a8da-811182de622d
< 1.1.1
MEDIUM 4.3 The Laposta Signup Embed plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1… wordfence
12b808a9-93d8-4fd4-b194-044f3a5376b8
< 5.1.4
MEDIUM 4.3 The Bold Page Builder plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capabilit… wordfence
← Prev 1565 1566 1567 1568 1569 1570 1571 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top