🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1574 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0cd1ded8-d8e8-48d2-bf6a-7041bd220fb2
< 1.70.236
MEDIUM 4.3 The WP Fast Total Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
0cb5df54-a6a7-4c2e-8df0-5d050218622e
< 4.6.15
MEDIUM 4.3 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized data access due to … wordfence
0cb21974-7745-4765-825f-adeca7e589e1
< 2.4
MEDIUM 4.3 The Social Reviews & Recommendations plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… wordfence
0cae43cb-a0b7-4067-95b3-26fec31ebf42 MEDIUM 4.3 The Popover Windows plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
0ca7291d-1309-4129-8244-cff6b6de45c0
< 1.1.7
MEDIUM 4.3 The WP Duplicate – WordPress Migration Plugin plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
0c943b6b-9b54-4569-a027-11571f152b6c
< 1.17.7
MEDIUM 4.3 The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization b… wordfence
0c88c526-5978-4319-885b-8edac3f028a4
< 2.4.8
MEDIUM 4.3 The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio… wordfence
0c6bc786-341a-4ab6-b86e-d21bb3dbf298
< 1.3.4
MEDIUM 4.3 The WP VK-付费内容插件 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
0c676a46-3e3f-4dc0-ba7f-acf1f100fb4a
< 1.16.9
MEDIUM 4.3 The MultiParcels Shipping For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
0c5e3ca4-fbba-4428-ab3b-e955aa9f60d4
< 1.3.0
MEDIUM 4.3 The OwnerRez plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.2.6. This… wordfence
0c533277-5cea-419f-93ec-e510c0fbd75d
< 2.3
MEDIUM 4.3 The EnvíaloSimple plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
0c467a78-1ba4-4c0d-84e6-db54fc1b0c63 MEDIUM 4.3 The WPCargo Track & Trace plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
0c29e242-b05c-4876-8948-1278982d6fbc
< 2.1
MEDIUM 4.3 The 3DPrint Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
0c1c8310-76c3-4505-9504-993e594804a4
< 8.12
MEDIUM 4.3 The WP LinkedIn Auto Publish plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… wordfence
0c06880e-06cc-4204-a031-355de4de3af2
< 2.5.3
MEDIUM 4.3 The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
0c05dcd9-71d2-4881-b5aa-335821ff95b3
< 3.4.4
MEDIUM 4.3 The Recipe Card Blocks for Gutenberg & Elementor – Best WordPress Recipe Plugin plugin for WordPress is vulnerable to … wordfence
0beaa7ce-40aa-429e-80fd-d04e75489b92 MEDIUM 4.3 The Custom Header Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
0be8c668-0f1c-4f83-8a71-49c8bb9b67ae
< 4.0.7
MEDIUM 4.3 The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability… wordfence
0be6658d-aec8-404c-a994-bde10a3cdbac
< 3.1.7
MEDIUM 4.3 The WSChat – WordPress Live Chat plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
0be418fa-f1cf-4aaf-bc94-c8e04186a54b MEDIUM 4.3 The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the ladiflo… wordfence
0be21ac7-4f61-44fc-9ffc-ab65faa549f6 MEDIUM 4.3 The tencentcloud-cos plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
0bde3052-ae8e-4434-962a-88d3c8328a9c
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capabili… wordfence
0bcc1457-abbc-4bd9-a0a8-80e3d5624d95
< 2.6.1
MEDIUM 4.3 The YITH WooCommerce Waiting List plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
0bc7f5dd-a1eb-442d-9913-e391208e7f26 MEDIUM 4.3 The Ajax Pagination and Infinite Scroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
0bc772a6-95a1-4420-bd97-1778002e2168
< 2.2.12
MEDIUM 4.3 The TK Google Fonts GDPR Compliant plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
← Prev 1571 1572 1573 1574 1575 1576 1577 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top