πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1573 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0e0e0c15-caf6-4166-a365-a2a73cd9ebc4
< 7.2.2
MEDIUM 4.3 The WoodMart theme for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing cap… wordfence
0e05bad8-2093-4ca8-8c24-ae513ae4f1b9 MEDIUM 4.3 The Pay with Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
0e03aeed-abb3-4ac8-8ff5-72ddc2430b94
< 2.2.0
MEDIUM 4.3 The WP Matterport Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
0dfc8957-78b8-4c55-ba95-52d95b086341
< 2.5.0
MEDIUM 4.3 The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads … wordfence
0de689a0-3f4e-4d2c-865b-deed36716f05
< 1.5.4.2
MEDIUM 4.3 The JetTricks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
0dd93514-657c-4b04-931a-23f3d405fb88
< 1.8.1
MEDIUM 4.3 The Qi Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … wordfence
0dc29b0c-3325-4524-8848-4857d5aa204e MEDIUM 4.3 The Aioseo Multibyte Descriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
0dbce573-fced-4c0f-ba1e-2932c166545c
< 4.9.3
MEDIUM 4.3 The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
0da1cc3b-5d6b-4ca0-9d8a-31c63ab5b9c9
< 4.1.38
MEDIUM 4.3 WordPress Core is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the β€˜wp_ajax_set_attachm… wordfence
0d9d32fd-a3ec-40f6-a38f-faa4b354e4d4 MEDIUM 4.3 The Oganro Travel Portal Search Widget for HotelBeds APITUDE API plugin for WordPress is vulnerable to Cross-Site Reques… wordfence
0d98c849-4178-4cee-846b-2c136bc56daf
< 1.5.16
MEDIUM 4.3 The WooCommerce Checkout & Funnel Builder by CartFlows plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
0d8bc203-c17a-4b31-8f9e-695f9e638cda
< 4.9.7.1
MEDIUM 4.3 The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized … wordfence
0d82ab22-da6d-4526-a70a-519589b29187
< 1.9.7
MEDIUM 4.3 The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers t… wordfence
0d758977-2e78-4395-bd18-7f25aecf8a55
< 2.27.0
MEDIUM 4.3 The WP Umbrella: Security Backup Restore & Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
0d54e5ad-0a97-4dd4-b53b-ad3f885dc506
< 2.2.0
MEDIUM 4.3 The Tracking Code Manager plugin for WordPress is vulnerable to unauthorized modification due to a missing capability ch… wordfence
0d2dc86e-f937-429f-9baa-0eb0a8715513
< 2.03
MEDIUM 4.3 The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… wordfence
0d2bd628-4df2-47f3-a9c8-35f544fc240c
< 1.53.2
MEDIUM 4.3 The Broadstreet Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
0d1ff67c-f644-46d1-abad-e5fc2b177786 MEDIUM 4.3 The WZone plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
0d195034-4617-474d-a4b1-b299c1607f89
< 1.1.10
MEDIUM 4.3 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
0d1456bb-9ecb-406e-b1c8-b582bee094a9
< 3.0.2
MEDIUM 4.3 The Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart plugin for WordPress is vulner… wordfence
0d00b50c-949a-4fd0-9eab-3555d263fcc7
< 6.3.4
MEDIUM 4.3 The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized post dupl… wordfence
0cf9c390-81d7-45d4-a6df-22b16235d11b MEDIUM 4.3 The Recent Posts Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
0cf65972-a651-41b0-8f57-709e0ff685fa
< 2.1.11
MEDIUM 4.3 The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
0cefa293-c934-413e-b946-07e3060472ee
< 4.1.6
MEDIUM 4.3 The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a … wordfence
0cef43a2-7917-4abd-b8f5-4a7604eadb70
< 3.06.0
MEDIUM 4.3 The WebinarIgnition plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… wordfence
← Prev 1570 1571 1572 1573 1574 1575 1576 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top