πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1588 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
40957153-45f1-40c9-91ce-f3491ca7eee5
< 3.5.2.1
LOW 3.8 The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,… wordfence
3dfba044-42f8-44a2-be62-99af9d9094c3
< 3.5.2
LOW 3.8 Advanced Custom Fields up to 3.5.1 is vulnerable to Remote Code Execution. The vulnerability allows for remote file incl… wordfence
369cd6ca-bb36-479e-b342-36d2ca778ce1 LOW 3.8 The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and incl… wordfence
342370a0-9364-40cd-9556-e53312e67548
< 3.4.2
LOW 3.8 wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-admini… wordfence
2f5962e5-3dc7-4f93-889c-d5e3530c7dba
< 0.9.129
LOW 3.8 The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory … wordfence
2a7f64e1-c815-426b-99cc-03ab62aaf9de LOW 3.8 The wp2syslog plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.5 … wordfence
28d3fe13-20f8-48af-9476-98d2bef467e5
< 1.7.16
LOW 3.8 The WP YouTube Lyte WordPress plugin before 1.7.16 did not sanitise or escape its lyte_yt_api_key and lyte_notification … wordfence
2760ee88-b8fc-4390-a92a-829e3e9401d8
< 1.4.37
LOW 3.8 The CP Multi View Event Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
2154383e-eabb-4964-8991-423dd68d5efb
< 4.23.6
LOW 3.8 The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… wordfence
1ead1a18-9429-472e-9e88-e792eaa23ae9
< 6.8.1
LOW 3.8 The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.… wordfence
13d0eb8a-5b63-460e-b4ba-a3ed80c84fc2
< 1.4.15
LOW 3.8 The CP Multi View Event Calendar plugin for WordPress is vulnerable to Insufficient Authorization in versions up to, and… wordfence
f1c08c10-7358-4618-b892-7d222ba460de
< 1.2.0
LOW 3.7 The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (Re… wordfence
e5dc87cd-4f45-4faf-b1e2-64e94eacb180
< 6.8
LOW 3.7 Versions of WordPress core older than version 6.8 use a weak MD5-based password hashing algorithm, which makes it easier… wordfence
d88a5dfc-4654-4299-b5a5-2a48b3823e37
< 2.0.9
LOW 3.7 Multiple plugins for WordPress utilize a vulnerable dependency (PHPExcel) in various versions. No vulnerabilities have b… wordfence
d72cc420-1ff5-403b-b4ea-7c820fdebcf3
< 4.1.1
LOW 3.7 The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Se… wordfence
d3f4de75-abf5-46e8-854d-be91ed74a5f3
< 3.3.5
LOW 3.7 The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. T… wordfence
CVE-2026-1582 LOW 3.7 The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… nvd
c66bc0b1-c157-4c05-ae9d-0927863c6b95
< 1.4.4
LOW 3.7 The Job Manager & Career – Manage job board listings, and recruitments plugin for WordPress is vulnerable to Sensitive… wordfence
bb81e90f-8da4-483c-9bc1-18b6c016df5e
< 1.9.12
LOW 3.7 The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in all versions up to, and including, 1.9… wordfence
ba2515d9-ced0-4b49-87c4-04c8391c2608
< 4.2.2
LOW 3.7 The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded e… wordfence
ae342dd9-2f5f-4356-8fb4-9a3e5f4f8316
< 2.4.19
LOW 3.7 The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.1… wordfence
a07bc541-2113-43db-acdf-9ecb00dd50e9
< 0.9.5
LOW 3.7 The W3 Total Cache plugin for WordPress is vulnerable to authorization bypass due to the use of loose comparison on the … wordfence
9a92c682-b8b3-4d23-bd84-97d7440ee525
< 1.4.15
LOW 3.7 The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
8b507369-49f7-4a1d-900b-c7bef40aec96
< 7.4
LOW 3.7 The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing ca… wordfence
78203b98-15bc-4d8e-9278-c472b518be07
< 2.38
LOW 3.7 The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and informati… wordfence
← Prev 1585 1586 1587 1588 1589 1590 1591 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top