πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1578 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
08b8f1ad-f616-4ceb-9c53-9d53aac370c9
< 2.9.5
MEDIUM 4.3 The Loan Repayment Calculator and Application Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
08b75cac-7b1d-4bed-a1b7-bd1e872f2b4f
< 1.5.3
MEDIUM 4.3 The Fatal Error Notify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
08b18825-9c2f-4304-afbe-7e4dc1b81227 MEDIUM 4.3 The WP-EasyArchives plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… wordfence
08b0f5e0-f68a-4fea-9d62-468956012a6d
< 1.9.4
MEDIUM 4.3 The Envo Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.3 vi… wordfence
08a98c08-cddc-4bc3-bc07-15d084070abd
< 4.6.0
MEDIUM 4.3 The WooCommerce Subscription for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and not includ… wordfence
0888cda8-63ca-44f6-a3eb-765c14a7e6c7 MEDIUM 4.3 The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2… wordfence
086eea65-9669-4397-9e35-76df4ee31e70 MEDIUM 4.3 The Similarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.… wordfence
086a32cc-f3af-4dab-921e-9ae6d1b73ae8
< 2.0.2
MEDIUM 4.3 The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Sensitive Information… wordfence
085da0fa-9487-4938-94ea-c1593be7c023 MEDIUM 4.3 The WPQA - Builder forms Addon For WordPress plugin is vulnerable to insecure direct object reference in versions up to,… wordfence
08511020-6129-4f55-a25e-7ed86efa721d
< 1.0.10
MEDIUM 4.3 The Syncee – Global Dropshipping plugin for WordPress is vulnerable to to Missing Authorization to Sensitive Informati… wordfence
084d0604-096d-4fec-a764-13e5c163ab5e
< 1.1.6
MEDIUM 4.3 The CubeWP Forms – All-in-One Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
0849d86b-5cf1-4346-a9e9-a54768837969
< 1.5.0
MEDIUM 4.3 The Admin Notices Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability … wordfence
08450bde-e5cf-4fc9-8df8-99d6d24bc3bf MEDIUM 4.3 The Hacklog Remote Image Autosave plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
08139129-8d9b-4cb7-b7c9-6fd0e2cb740a MEDIUM 4.3 The Patricia Lite theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.… wordfence
080f3a37-ed11-456c-8c2a-4120bb6fa189
< 3.16.3
MEDIUM 4.3 The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized access in all versio… wordfence
08057fa2-90e1-4537-a828-a2c5902b348c
< 1.8.2
MEDIUM 4.3 The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all … wordfence
07fa7b1a-9137-4049-a20a-8eb6df7ca578
< 2.11.21
MEDIUM 4.3 The Tourfic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.11.… wordfence
07f343cd-5181-48a3-bee7-a60dd9771d07
< 1.30.1
MEDIUM 4.3 The Equalize Digital Accessibility Checker – Audit Your Website for WCAG, ADA, and Section 508 Accessibility Errors pl… wordfence
07ebb174-656b-4761-ada0-557e0384d003 MEDIUM 4.3 The i-transform theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.9.… wordfence
07cb3d57-d768-49a5-8af0-9dc4384487d5
< 5.4.0
MEDIUM 4.3 The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to u… wordfence
07c92f79-94ac-4153-9ab2-9608601508b0
< 3.3.2
MEDIUM 4.3 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification … wordfence
07b96ff4-bd2b-4089-8c6a-6196dc678fb1
< 1.4.1
MEDIUM 4.3 The Swiss Toolkit For WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
07b7c6ed-c3dc-4daa-8921-eeb856e45386
< 2.5.15
MEDIUM 4.3 The SVG Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
07a82335-d738-4c14-b385-04843f12e4ef MEDIUM 4.3 The WP Users Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.… wordfence
07a69a69-de18-4a31-97aa-380b8499a4eb
< 1.4.16
MEDIUM 4.3 The The Events Calendar Countdown Addon plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
← Prev 1575 1576 1577 1578 1579 1580 1581 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top