πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1569 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
12a94f5b-bc30-4a65-b397-54488c836ec3
< 1.57.0.10
MEDIUM 4.3 The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' funct… wordfence
12a195a0-f992-462d-9b4e-69e8a2975635
< 5.0
MEDIUM 4.3 The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to Cross-Site Reque… wordfence
12959cc5-d088-4e2c-8658-e54900839aa6
< 1.91.3
MEDIUM 4.3 The FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration plugin fo… wordfence
12913ac3-82a7-42e9-ba44-8e6577e0fbc7 MEDIUM 4.3 The DB Backup plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
128bc7ee-9763-415f-b726-0e63d4b62271
< 4.1.4
MEDIUM 4.3 The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thew… wordfence
127b20c4-cd7c-4d04-b32f-bcc26beb2c35
< 4.1.5
MEDIUM 4.3 The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
127691c4-dc63-44e0-b591-b342a3809888
< 3.2.43
MEDIUM 4.3 The Cost Calculator Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
12735e6b-9ed5-4bf6-ab72-36a5218fa43c MEDIUM 4.3 The Bknewsticker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
126e2b92-322e-440c-a924-1b604330f164
< 4.5.6
MEDIUM 4.3 The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in… wordfence
126c77fa-11c5-431f-8fc9-0375ed6c8a91
< 4.23.13
MEDIUM 4.3 The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unau… wordfence
1268604c-08eb-4d86-8e97-9cdaa3e19c1f
< 5.4.9
MEDIUM 4.3 The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8… wordfence
125eb557-0566-48e2-a966-f9255e877e0f
< 8.2.5
MEDIUM 4.3 The WP Customer Area plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
123c0279-a7f6-4a4b-a5e1-79702e295303
< 2.5
MEDIUM 4.3 The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
1237f0b3-540a-4734-8966-4798799fef65
< 2.7.0
MEDIUM 4.3 The Slugs Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6… wordfence
121cad41-d3cd-4042-b568-3d91909a38d3
< 3.7.4
MEDIUM 4.3 The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
1218ed3b-badc-464e-adbc-76fb4f6af008
< 3.2.6
MEDIUM 4.3 The Google Calendar Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
1213a21f-a9c1-4da3-99b5-4a5a0673073f
< 6.3.0
MEDIUM 4.3 The WP Plugin Info Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
120a75c5-4fff-4a77-b376-d6968853b40e MEDIUM 4.3 The WP Social Bookmark Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
11fc48b0-cee2-4392-866b-5c0f366e5d98 MEDIUM 4.3 The Language plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up … wordfence
11f74b86-a050-4247-b310-045bf48fd4bd
< 1.7.2
MEDIUM 4.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
11ea3e40-8802-43ea-9816-973a15d7904d
< 2.2.2
MEDIUM 4.3 The WP OnlineSupport, Essential Plugin Popup Anything plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
11e31621-295a-4d34-8f11-65408bc75260
< 3.1.83
MEDIUM 4.3 The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Cross-Site… wordfence
11cc8c6e-b60e-46b3-966e-07b1fb2bf8e9
< 1.2.7
MEDIUM 4.3 The WP Affiliate Disclosure plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
11c4b855-8589-4ad2-b414-566ac8eb4632
< 5.2.0
MEDIUM 4.3 The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks… wordfence
11bdcf58-be0c-4fdb-ac15-ee4c3afe7275
< 1.7.6
MEDIUM 4.3 The Loginizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.5. … wordfence
← Prev 1566 1567 1568 1569 1570 1571 1572 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top