πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1571 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
10546cbe-17ba-481a-b464-18d83fab8b32
< 2.0.1
MEDIUM 4.3 The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up … wordfence
102982a5-23c3-40e1-99c4-34b013ec7712 MEDIUM 4.3 The Auto Tag Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
1023edcb-9879-4dde-b62e-3ce65d7fef2f
< 2.0.5
MEDIUM 4.3 The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
101fd983-bf41-4d3f-81a3-ddc14c55dfea
< 1.7.3
MEDIUM 4.3 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
101dd211-c3eb-4d27-9194-841bc2a968e6
< 7.13.55
MEDIUM 4.3 The Super Socializer plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability c… wordfence
100b6786-7cad-4d65-b457-9beb179e293a
< 2.10.7
MEDIUM 4.3 The Simple Job Board plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
0febc283-6c4a-472a-a211-0df853d63f7b
< 1.1.35
MEDIUM 4.3 The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to… wordfence
0fe987f0-6887-4ad1-a748-eb987bb574fa MEDIUM 4.3 The imwptip plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. … wordfence
0fe2bc91-2c8a-46ca-99cb-187d5c688305
< 1.1.7
MEDIUM 4.3 The Virusdie – One-click website security plugin for WordPress is vulnerable to Sensitive Information Exposure in all … wordfence
0fe28cf5-466d-4a28-b6bd-6d77c54b97f9
< 9.5.3
MEDIUM 4.3 The WordPress Tooltips plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
0fd0928c-801d-4449-a5e5-536e3fb902e9
< 3.10.0
MEDIUM 4.3 The Sugar Calendar (Lite) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
0fb8e956-3a95-4e55-9816-be7eddb5835d
< 7.1.8
MEDIUM 4.3 The Theme My Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
0fb06de8-97d6-46c3-83ef-93a209540259
< 2.1.1
MEDIUM 4.3 The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Re… wordfence
0facb49f-7276-4f50-862d-5d421026b0a8 MEDIUM 4.3 The Kenta Companion plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
0fa84344-8672-43e1-a430-094021f7366f
< 1.5.1
MEDIUM 4.3 The Simple Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
0f963cd2-0069-4e58-a5e5-8a9bfea65168
< 2.6.0
MEDIUM 4.3 The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_ima… wordfence
0f9229f2-e7dd-43c9-9c15-9b76c13e895b
< 2.1.14
MEDIUM 4.3 The iThemes Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.… wordfence
0f88631c-25d2-4b67-91b3-a4f0168623ec MEDIUM 4.3 The Roam - Travel & Tourism WordPress Theme theme for WordPress is vulnerable to Insecure Direct Object Reference in all… wordfence
0f704143-8842-485c-b419-f78b903b4184
< 1.0.2
MEDIUM 4.3 The Chakra test plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
0f6be03e-1aa1-4e34-b899-90a55423a80b MEDIUM 4.3 The Eventer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
0f4ecda0-1eaa-44e7-8ef5-20c967b5da9f
< 0.1.43
MEDIUM 4.3 The Contact Form 7 AWeber Extension plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… wordfence
0f473b8a-26c7-4a91-aed1-d7df1506c8f9 MEDIUM 4.3 The Coder for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
0f3f5429-f328-4000-a9ac-7d828f9386fc
< 1.9.94
MEDIUM 4.3 The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable t… wordfence
0f3df75e-cf2f-4076-b5ff-b8540408044a
< 1.5.0
MEDIUM 4.3 The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
0f1f0b69-1c38-45e9-a3d6-b7a85f6ed78c
< 2.6.1
MEDIUM 4.3 The Prevent files / folders access plugin for WordPress is vulnerable to Path Traversal in all versions up to, and inclu… wordfence
← Prev 1568 1569 1570 1571 1572 1573 1574 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top