ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1584 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
02a9a673-4e6b-4c06-b752-88b4ecf55d70
< 3.12.5
MEDIUM 4.3 The Email Marketing Plugin – WP Email Capture plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
02822b64-7cfb-4cd1-a727-10f61603ece4
< 3.5.7.2
MEDIUM 4.3 The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to unauthorize… wordfence
025d576b-7342-4863-ac30-f1ff0205d638
< 3.1.2
MEDIUM 4.3 The TS Webfonts for ã•ãらã®ãƒ¬ãƒ³ã‚¿ãƒ«ã‚µãƒ¼ãƒ plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
025a06c7-6573-4074-af4c-7b5836081943
< 6.2.5
MEDIUM 4.3 The Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… wordfence
0253e3fa-c0ee-4c76-bd92-a450771cae0c
< 2.3.3
MEDIUM 4.3 The Fraud Prevention For WooCommerce and EDD plugin for WordPress is vulnerable to Sensitive Information Exposure in all… wordfence
024fa9ff-d1ba-4c1f-aa51-1dbf5a5713d8
< 5.6.4
MEDIUM 4.3 The ShortPixel Image Optimizer plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
024f4058-065b-48b4-a08a-d9732d4375cd
< 1.1.3
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
02490a4b-b2c0-4921-bbf2-678c44c96a5b
< 1.2.26
MEDIUM 4.3 The Fastly plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check … wordfence
02409698-5421-4760-afcd-e53939082bfc
< 3.0.2
MEDIUM 4.3 The Bubble Menu – circle floating menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
0219851f-7fce-42e0-ba82-77af84b17d9f
< 4.4.10.6
MEDIUM 4.3 The WpStream – Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to Cross-Site Request … wordfence
0210637e-360b-422f-be96-43e6ac48fe64 MEDIUM 4.3 The Clever Mega Menu for Visual Composer plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
020df8cb-a9ce-4f04-b88f-ceb988beeb75
< 0.9.5.9
MEDIUM 4.3 The WPCal.io – Easy Meeting Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
0206aead-d146-453d-99ed-3870f7dfdae9
< 0.7.9
MEDIUM 4.3 The Maspik plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.7.8. Th… wordfence
01ec3ba3-4627-4072-b15d-44e98c652836
< 4.9.11
MEDIUM 4.3 The Slim SEO plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.… wordfence
01eaa600-6ddf-492b-b2cf-ca560ce71db5 MEDIUM 4.3 The SpicePress theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.2.5… wordfence
01e1b22f-9622-433f-bada-23d118dc3800
< 2.0.2
MEDIUM 4.3 The Simple Admin Language Change plugin for WordPress is vulnerable to authorization bypass due to a missing capability … wordfence
01d115b7-38a7-4dfd-ac81-4d7ce71969b2
< 3.2
MEDIUM 4.3 The Interact: Embed A Quiz On Your Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
01cc3955-ef2f-4e2b-8dc6-b26f5a3d2f89
< 1.3.14
MEDIUM 4.3 The Dynamics 365 Integration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… wordfence
01c8d909-ecfd-4443-9bef-e1b541e74c2b
< 1.1.0
MEDIUM 4.3 The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable… wordfence
01bacc7f-9b17-4889-88f2-fcf55f3e61d5 MEDIUM 4.3 The Co-marquage service-public.fr plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
01b90498-0ddb-4eb3-b76d-de30ed03d7d0
< 1.6.4
MEDIUM 4.3 The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… wordfence
01abc69a-65c3-4acc-b190-efd8da2ec76f MEDIUM 4.3 The Payment Forms for Paystack plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, a… wordfence
01a6a5bf-636b-416c-86fa-43f639624e80
< 2.9
MEDIUM 4.3 The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on th… wordfence
01a3b9ba-b18a-48d9-8365-d10f79fc6a6b
< 2.6.2
MEDIUM 4.3 The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a… wordfence
01996a4c-0ad8-4da8-bfa7-3442c5a67679 MEDIUM 4.3 The WidgetPack Comment System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
← Prev 1581 1582 1583 1584 1585 1586 1587 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top