πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1577 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
09b2d763-63ce-4cc7-aa04-589bb8697ce9 MEDIUM 4.3 The Newsletter2Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
09b26b78-b587-42f6-a9e3-c2945e91d29e
< 5.8.0
MEDIUM 4.3 The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Di… wordfence
09ac79b4-f072-4f15-9f4d-89d0bcdf8fa3
< 1.3.0
MEDIUM 4.3 The AI Content Creator – Easy ChatGPT powered article generator plugin for WordPress is vulnerable to Cross-Site Reque… wordfence
09a4e0e6-3be4-4f55-8816-8eeb3e24f2ca
< 3.5.5.8
MEDIUM 4.3 The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
099b8d92-6806-445f-aec9-514dce53fc5f
< 3.3.201
MEDIUM 4.3 The Zephyr Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
09932277-8af3-4790-96f0-fe5af0a0ed29
< 1.2.35
MEDIUM 4.3 The Booking Calendar Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
09779cc3-96ea-4b50-b28c-c5690edf082f
< 3.8.3.3
MEDIUM 4.3 The Pie Register Premium plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.8.… wordfence
0968fe3b-2256-41e8-8cc9-e800dd7f8c27
< 1.6.0
MEDIUM 4.3 The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable… wordfence
0966057b-8a3c-4d3c-84cb-cf36f1d97922
< 4.4.6
MEDIUM 4.3 The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
096257a4-6ee9-41e1-8a59-4ffcd309f83c
< 1.1.3
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
09551d22-c8c2-435c-9d00-bb4833497c16
< 1.2.92
MEDIUM 4.3 The Ashe Extra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
09547dae-85dc-481d-9eb1-423d8faadc80
< 2.2.0
MEDIUM 4.3 The Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
094bf4e2-b774-4015-b6c6-c829c16556eb
< 1.4.1
MEDIUM 4.3 The WP Pipes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. T… wordfence
0931f279-2dac-4663-9344-df27b43a7e64
< 6.1
MEDIUM 4.3 The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an… wordfence
0930e4f2-125f-4d37-a051-418f5e8c536d
< 5.22
MEDIUM 4.3 The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to unauthorized access due to a m… wordfence
0920fc70-1c4b-45ff-86f6-14640286b5e6
< 3.0.1
MEDIUM 4.3 The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
0913da2d-2512-436f-ae65-3a83e221c618
< 3.2.0
MEDIUM 4.3 The BOX NOW Delivery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
09020bbf-6222-4a75-b01f-cfd615a44765 MEDIUM 4.3 The Altra Side Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
0901533b-1be7-4c94-8f9e-dc63e3e441ef
< 7.2.14
MEDIUM 4.3 The Conversios.io plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
08f4445b-9c79-42e3-be45-d07f72c00a01
< 1.6.22
MEDIUM 4.3 The ReviewX plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the remote_po… wordfence
08ec2376-dfe3-4aeb-8173-01e88309f540
< 5.3
MEDIUM 4.3 The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized mo… wordfence
08e44434-8908-4c63-9e5b-9a8b387255d9
< 1.0.16
MEDIUM 4.3 The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in… wordfence
08d43c67-df40-4f1a-a351-803e59edee13
< 1.3.0
MEDIUM 4.3 The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecur… wordfence
08ccd4a3-ea1f-49b3-b4ce-ab1e247e1f76
< 2.7.2
MEDIUM 4.3 The Country State City Dropdown CF7 plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… wordfence
08c79118-9dad-44fd-b683-7950276d3808
< 1.0.7.5
MEDIUM 4.3 The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
← Prev 1574 1575 1576 1577 1578 1579 1580 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top