πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1570 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
118eedee-3816-49e3-b924-f4ed67eede3e MEDIUM 4.3 The WordPress Testimonials Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
118e1a8c-a638-4571-9ce9-cf2cba4b9b06
< 118
MEDIUM 4.3 The Simple URLs plugin for WordPress is vulnerable to unauthorized utilization of AJAX functionality due to a missing ca… wordfence
1171a510-ae5c-4f8e-99a2-aa98cf54d82e
< 5.1.1
MEDIUM 4.3 The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
1165c68d-3da4-45f3-b054-4904e54d18ac MEDIUM 4.3 The Google XML Sitemap for Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
1161af9d-89f7-429f-a481-5a3008f3be8a
< 1.9.6
MEDIUM 4.3 The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
114e8ba9-b6b0-4b54-982c-8e9efaa616c7
< 4.9.11
MEDIUM 4.3 The Spiffy Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the a… wordfence
113f0cb7-a5eb-42d5-ad42-871c0381b617 MEDIUM 4.3 The Keap Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
113b3093-18fe-40ae-85af-aae1945201db MEDIUM 4.3 The RD Contacto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
113aa171-c5b2-4cb0-808d-cd56594bacb1
< 2.7.13
MEDIUM 4.3 The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
1127fe1e-4359-4dff-93a7-392a8bfded51
< 3.2.4
MEDIUM 4.3 The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPre… wordfence
110e5e67-b318-4ab2-9b4d-59aabcf7db7c
< 2.12.7
MEDIUM 4.3 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Path Traversal in versions up to, and i… wordfence
10ffe689-143a-4232-8094-45844dc5262b MEDIUM 4.3 The FreshMail For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
10f00859-3adf-40ff-8f33-827bbb1f62df
< 2.11.2
MEDIUM 4.3 The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPr… wordfence
10dbed32-1766-4746-b820-3f17d774ba04 MEDIUM 4.3 The Shk Corporate theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
10dbaf83-03c4-409d-b31a-198eab101dd1
< 1.52.2
MEDIUM 4.3 The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
10cc54a9-4b3d-4584-a90e-7828cd9cdc26
< 1.0.97
MEDIUM 4.3 The Corpiva theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.96. Th… wordfence
10c17e74-dced-483e-bcaf-00ff5b11059c
< 10.6.1
MEDIUM 4.3 The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … wordfence
10a811f3-0c5b-4e06-a9bb-338d36d0b5eb
< 3.7.15
MEDIUM 4.3 WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the abilit… wordfence
1090acfc-5b0c-478a-ac71-db54fdaefdf5
< 1.3.6
MEDIUM 4.3 The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to unauthorized modification of data… wordfence
108fc77a-b260-4bbf-a551-7593bbecc6e0 MEDIUM 4.3 The ListingPro theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
108cd0dd-f5c9-4ca8-989e-0ae5384ff6c1 MEDIUM 4.3 The FPW Category Thumbnails plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
1089ab17-b780-4840-8dcd-c50258513634
< 2.2.1
MEDIUM 4.3 The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … wordfence
107cb15f-4b2e-4ed4-8e8a-4f716f4873db
< 1.6.5
MEDIUM 4.3 The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorizatio… wordfence
10735038-69dd-4b74-9374-38379832cdcb
< 3.1.10
MEDIUM 4.3 The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability … wordfence
10724b12-fbe4-4da1-b3f5-157b2702996d MEDIUM 4.3 The Media Author plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
← Prev 1567 1568 1569 1570 1571 1572 1573 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top