πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1579 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
07a58033-5c2d-4550-99ba-57037327a661
< 3.1.13
MEDIUM 4.3 The FooGallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
07a4101b-a46c-4e61-a23c-aaa341ee5bd7
< 2.3.18
MEDIUM 4.3 The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
079b5c51-1e59-400c-ad68-10dab1f105b3
< 5.9.9.7
MEDIUM 4.3 The ProfileGrid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
0790f2ec-8d83-4b0e-9eaf-2891917529e7
< 1.6.3.1
MEDIUM 4.3 The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
078a0647-fc3a-436c-bf00-8776b16e66ff
< 4.1.0
MEDIUM 4.3 The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,… wordfence
0788095e-38d0-49cf-b8e1-1f25e3b4e795
< 2.6.0
MEDIUM 4.3 The Doppler Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
078603e7-d597-4090-9c53-14ed98674269
< 30.0.7
MEDIUM 4.3 The Contest Gallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
0775b36b-d543-41f9-a20d-f629b40c70d7
< 5.3
MEDIUM 4.3 The Configurable Tag Cloud plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
076e79f0-88db-4216-8920-7c16ace4f07b MEDIUM 4.3 The SEO Backlink Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
076e063d-716f-4b45-af23-83d1deec4af4 MEDIUM 4.3 The RIS Version Switcher – Downgrade or Upgrade WP Versions Easily plugin for WordPress is vulnerable to Cross-Sit… wordfence
0767e5ef-477f-4b0c-a86e-6298614c9777
< 11.2.4
MEDIUM 4.3 The Quiz And Survey Master plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and… wordfence
07663fae-53e9-45d2-834c-6e1392484e0a MEDIUM 4.3 The Who Hit The Page – Hit Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
076526c3-a188-49a0-afcb-85c1f8d5d605 MEDIUM 4.3 The Change Cart button Colors WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
075dce39-f06c-4ab3-a1ec-2669f32a81ab
< 3.8.0
MEDIUM 4.3 The WP Configurator Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
074d995e-42cc-42f0-bdbe-de181180b511
< 1.3.0
MEDIUM 4.3 The Dashboard To-Do List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
074d7b46-60e0-4d4a-904a-696ac7948a35
< 7.3.0
MEDIUM 4.3 The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
0748838a-191a-4dde-80c9-7898c1de6adc
< 3.9.0
MEDIUM 4.3 The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, El… wordfence
07300429-c445-4d2a-90aa-5072a17f8113
< 6.4.5
MEDIUM 4.3 The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
072a1fb5-aedc-4556-909f-61bbda37dfa2
< 11.14
MEDIUM 4.3 The PowerPress Podcasting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
071cbf50-3af4-4d61-8f49-e967e30294be
< 1.3.59
MEDIUM 4.3 The Contact Form Email plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
06f4e758-3328-4ac1-956a-cfadddd12e53
< 1.0.7
MEDIUM 4.3 The Simple Bike Rental plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che… wordfence
06efa097-38dc-4499-b163-7a6254b25f72 MEDIUM 4.3 The WP Meta Sort Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
06ef2a3b-96d5-40eb-8b35-2b4e3d90f7f6
< 2.4.7
MEDIUM 4.3 The Doppler Forms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
06ec9ff7-1dd5-4b9b-8f15-cd9523a708a1
< 2.9.3
MEDIUM 4.3 The Alo Easymail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.… wordfence
06dfc5d3-3d11-4091-9253-248f799dee75
< 3.8.0
MEDIUM 4.3 The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vul… wordfence
← Prev 1576 1577 1578 1579 1580 1581 1582 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top