πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1575 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0bb90162-314a-4d49-8fd3-2b1b42c5ad63
< 3.0.3
MEDIUM 4.3 The Calendarista Basic Edition plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
0bb28557-7023-481f-a05b-0b9a22d7a456 MEDIUM 4.3 The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including… wordfence
0bac75e0-f7cb-44b8-8267-043b359a8671
< 3.5.5.3
MEDIUM 4.3 The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
0b9f4615-278f-4762-98ce-5c9d806da1a5
< 1.3.5
MEDIUM 4.3 The Education Zone theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3… wordfence
0b92afdf-51e0-4cf5-9f2b-997b9ff98b23
< 1.7.0
MEDIUM 4.3 The Post Carousel Slider for Elementor plugin for WordPress is vulnerable to improper authorization due to a missing cap… wordfence
0b922cd8-870e-4297-bd75-7e8f3e7e6e1f
< 4.3.3
MEDIUM 4.3 The Related Posts Thumbnails Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… wordfence
0b82fae0-4eec-41ea-90e2-9d08258805b3
< 2.11
MEDIUM 4.3 The Sp*tify Play Button for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
0b80e90d-72bd-4253-b84b-d2706e1abd4c
< 4.5.16
MEDIUM 4.3 The LiveChat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.15. … wordfence
0b751496-86b1-4480-98d6-28579e4044a0 MEDIUM 4.3 The The League theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
0b4a0dff-1054-4f50-8ff5-e3cc2b45d77b
< 1.0.26
MEDIUM 4.3 The Image Optimizer by 10web plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including,… wordfence
0b3fa78c-d97f-43bf-b3e9-47d6aa41b458
< 1.5.3
MEDIUM 4.3 The Advanced Local Pickup for WooCommerce for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
0afdc88e-7a0c-49a1-819e-cb1e263d1f78 MEDIUM 4.3 The Social Share Buttons & Analytics Plugin – GetSocial.io plugin for WordPress is vulnerable to unauthorized access d… wordfence
0af451be-2477-453c-a230-7f3fb804398b
< 2.6.0
MEDIUM 4.3 The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
0af3c74e-af3e-4dd5-9612-b1a573737276
< 2.1.3
MEDIUM 4.3 The Import CDN-Remote Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
0aea5564-b1b9-4d57-9f7e-81dd791c8d48
< 6.2.0.0
MEDIUM 4.3 The Community by PeepSo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
0ad981a8-1678-495c-b3dc-baa151aa0d9c
< 1.9
MEDIUM 4.3 The CSS3 Tooltips for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
0ad44770-91da-4265-b292-e6e41538d0f4
< 1.8.0
MEDIUM 4.3 The Cooked Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.8.0. This is due to … wordfence
0ac7a936-70fa-41ce-89f7-ec6a77964c96
< 3.3.3
MEDIUM 4.3 wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access… wordfence
0ac31c39-abbc-427f-aba3-d9ec3b51c4d2 MEDIUM 4.3 The Post Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.… wordfence
0abffda9-1f37-4e2a-9b85-2a7a204f1ed7
< 5.0
MEDIUM 4.3 The Add Custom Codes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
0abf6311-c66d-4318-8734-2237e46f2b6d
< 1.1.2
MEDIUM 4.3 The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
0abd5ca3-177f-43ef-b2ed-b3d7973c714e
< 2.8.7
MEDIUM 4.3 The Lobo - WordPress Portfolio for Freelancers & Agencies theme for WordPress is vulnerable to unauthorized access due t… wordfence
0a9793b6-2186-46ef-b204-d8f8f154ebf3
< 2.9.0
MEDIUM 4.3 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
0a94841f-b1dd-44f4-b7a1-65a9fdf7b18d
< 1.0.6.2
MEDIUM 4.3 The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is v… wordfence
0a941aef-85f6-4719-b6ab-ace77a03e93e
< 1.3.60
MEDIUM 4.3 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_… wordfence
← Prev 1572 1573 1574 1575 1576 1577 1578 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top