πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1572 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0f02cc66-7782-45fe-ae5e-340ff7ae1fe9
< 6.11.4
MEDIUM 4.3 The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
0efebdcb-c3fb-435a-8687-6abdd5f9334b MEDIUM 4.3 The Donations Made Easy – Smart Donations plugin for WordPress is vulnerable to unauthorized actions due to a missing … wordfence
0ef6a03b-8373-42e6-a15c-b99b22f5cee0
< 3.11.2
MEDIUM 4.3 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
0ef2953f-da65-422f-b893-833b49907c55
< 1.5.6
MEDIUM 4.3 The Portfolio and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… wordfence
0ef23749-21de-4c99-8fd6-4488ab16887e
< 7.2.0
MEDIUM 4.3 The WPC Frequently Bought Together for WooCommerce plugin for WordPress is vulnerable to unauthorized access and modific… wordfence
0eec9744-6dbd-42bd-b9c5-c9d792cecf4b
< 1.6.6.24
MEDIUM 4.3 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to C… wordfence
0edb6b7c-8a78-44b9-a5d6-b4a563c92484
< 1.1.28
MEDIUM 4.3 The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all ve… wordfence
0eb90948-b2b6-4e30-b903-95b7bce5d734
< 2.5.3
MEDIUM 4.3 The Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions plug… wordfence
0eb2c608-1a1f-4c74-aa24-b955db052559
< 6.3.0
MEDIUM 4.3 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unaut… wordfence
0ea9e69c-8a8e-41ab-99e7-f47d89ae0467 MEDIUM 4.3 The MSTW League Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
0e98a899-1578-45bf-ba1d-92703e38abd9 MEDIUM 4.3 The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
0e91d482-e417-4406-9156-b1dde0bf46e2
< 1.5.6
MEDIUM 4.3 The Featured Post Creative plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
0e843c18-fbd7-4413-86f9-8d72bcdcb9da
< 5.7.47
MEDIUM 4.3 The Quick Paypal Payments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
0e7130ca-f550-439c-81ec-e48737ff3956 MEDIUM 4.3 The Ultimate AJAX Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
0e69325d-49a9-4cd6-a359-7a926e77144e MEDIUM 4.3 The Konami Easter Egg plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
0e5cc0ce-3785-4240-863e-d1396db6e8ef
< 1.43.0
MEDIUM 4.3 The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnera… wordfence
0e477b9f-a2bf-4c2a-935b-82a93797f1bd
< 1.11.5
MEDIUM 4.3 The Bring Fraktguiden for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
0e454573-4b34-40e3-b4c3-10eb71dfa03e
< 1.2.4
MEDIUM 4.3 The Paid Memberships Pro - Courses for Membership Add On plugin for WordPress is vulnerable to Cross-Site Request Forger… wordfence
0e407409-989d-48f8-8135-6071015a6064
< 5.4.0
MEDIUM 4.3 The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable … wordfence
0e346146-1c00-4e03-a6c7-372566d7ffc9
< 1.14.14
MEDIUM 4.3 The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. … wordfence
0e2a2769-1309-4aad-8411-4445efea2b66
< 4.2.8.5
MEDIUM 4.3 The EventPrime plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization checks … wordfence
0e1d9c22-dcd3-47f9-aac0-c9626aa2821c
< 6.1.1
MEDIUM 4.3 The WPQA Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
0e1913e9-94bf-4466-b368-eba745f182be
< 1.0.1
MEDIUM 4.3 The GamiPress – Reset User plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
0e14b479-07bb-46f7-8542-577cb1b60d27
< 1.4.10
MEDIUM 4.3 The WP Search Analytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… wordfence
0e0f2516-0fa7-415e-868e-6bd259bc6546
< 5.0.0
MEDIUM 4.3 The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… wordfence
← Prev 1569 1570 1571 1572 1573 1574 1575 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top