πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1576 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0a7f2fc6-6932-4bf9-8c73-4a20f4c4bd68
< 7.8.2
MEDIUM 4.3 The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information E… wordfence
0a714536-c6fd-495b-b774-104657329a74
< 5.9.2
MEDIUM 4.3 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery… wordfence
0a6df89e-acd1-4b3d-ab51-6522b7bc13f6 MEDIUM 4.3 The Show Pages List plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
0a6b87a8-2ebf-4db6-bf09-e9642708b2aa
< 2.10.3
MEDIUM 4.3 The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
0a656052-3b8a-4a93-b4f8-372b448a8373
< 1.1.2
MEDIUM 4.3 The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, whi… wordfence
0a652464-73b7-4189-be80-2ee12fa25868
< 2.5.0
MEDIUM 4.3 The PostmarkApp Email Integrator plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
0a598274-3c67-4751-94d6-49abed38422c
< 1.7.7
MEDIUM 4.3 The Slideshow Gallery LITE plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
0a58d45b-c91b-4141-992e-336650d7252b
< 2.3.5
MEDIUM 4.3 The Automatic YouTube Gallery plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing… wordfence
0a49a22e-d54e-461d-83c2-8278494eac13
< 2.2.1
MEDIUM 4.3 The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… wordfence
0a4435e4-f057-4582-bc2d-2ab4c19ccaf4
< 1.2
MEDIUM 4.3 The Custom Fields Account Registration For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
0a43cc7c-1918-4a5a-a878-52e5d02b784b MEDIUM 4.3 The Grand Car Rental theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… wordfence
0a434d66-ac97-4801-8985-047dcc7c3eb4 MEDIUM 4.3 The Convert Post Types plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
0a41d0b9-da73-4d7a-b46e-ee74f4d0897d
< 1.1.7
MEDIUM 4.3 The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable… wordfence
0a2a29ea-3ff3-4b80-8a40-1a00491076ff MEDIUM 4.3 The Magazine Edge theme for WordPress is vulnerable to authorization bypass in versions up to, and including 1.13, due t… wordfence
0a1cf60b-47bd-4e67-8fe4-6cf46809f2b2
< 1.4.5
MEDIUM 4.3 The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u… wordfence
0a03184e-ab6f-4a71-9f1e-2bbe9a8b299e MEDIUM 4.3 The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized access due to a … wordfence
09fb88e4-4846-40d3-8a79-a6a867bfb59f
< 2.6.6
MEDIUM 4.3 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in al… wordfence
09f450bb-28c1-4c1e-ae13-afd53759e02f
< 1.1.6
MEDIUM 4.3 The FameTheme Demo Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
09f136e9-0888-456c-8bb6-e0300b601f05
< 7.4.0
MEDIUM 4.3 The FloristPress – Customize your Woo store for your Florist plugin for WordPress is vulnerable to unauthorized access… wordfence
09f01dcc-685b-485b-8572-cdf73d0157dc MEDIUM 4.3 The Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed plugin for… wordfence
09e5aa34-ab28-4349-ac5f-6a0479e641e5
< 6.4.3.1
MEDIUM 4.3 The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
09e5391d-2671-4bb4-9adc-29b5fdb59240
< 4.2.6
MEDIUM 4.3 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP… wordfence
09e28b72-55c6-4f2f-b689-a8989945651b MEDIUM 4.3 The WP Report Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
09bc815e-cf79-4d94-a934-366c251be551
< 1.3.3.1
MEDIUM 4.3 The WordPress Meta Data and Taxonomies Filter (MDTF) plugin for WordPress is vulnerable to unauthorized modification of … wordfence
09b68ffe-f8b2-4cde-b36e-b14da58d0bca
< 2.2.1
MEDIUM 4.3 The WP Crowdfunding plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 2.2.1 (… wordfence
← Prev 1573 1574 1575 1576 1577 1578 1579 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top