🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1589 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
72abfbcf-4be4-4e0a-89a7-94caa01c22a6
< 4.0.1
LOW 3.7 The LearnPress – Sepay Payment plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
68533b4c-1bdf-4104-a263-757b018af129
< 4.7.4
LOW 3.7 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to… wordfence
4f29d476-0730-437c-8065-309523278efa
< 2.1.6
LOW 3.7 The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper au… wordfence
4edbfeee-b668-4a85-a030-c15d6583dc82
< 5.16.1
LOW 3.7 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missi… wordfence
438e36ba-fd0e-4c98-814b-95f3d5f60d2f
< 2.10.14
LOW 3.7 The DOOFINDER Search and Discovery for WP & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Expo… wordfence
3bb93138-f2f9-4a3f-a0a2-d79a315c44f3
< 2.4.4
LOW 3.7 The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vu… wordfence
3a3fa988-6f0b-48d3-a946-0fc587858c9c
< 1.4.1
LOW 3.7 The WPSyncSheets Lite For Elementor – Elementor Pro Form Google Spreadsheet Addon plugin for WordPress was running sev… wordfence
334be95c-438a-4e03-9ee4-9a6d2c2fa5f7
< 3.4.3
LOW 3.7 The WP Job Openings plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includin… wordfence
30b4371d-54a2-4111-ad2c-b38b6b31884d
< 2.7.12
LOW 3.7 The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all version… wordfence
2f0d4f48-a315-4308-a5b6-7d3f045b292f
< 3.7.40
LOW 3.7 WordPress Core is vulnerable to information disclosure via a REST-API endpoint in versions up to 6.0.3. The endpoint for… wordfence
2d89a534-978e-4fd8-be3a-5137bdc22dc9
< 2.7.6
LOW 3.7 The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including… wordfence
2954a007-37ac-4811-a258-b3fdd738043f
< 2.4.4
LOW 3.7 The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are v… wordfence
1d3771ee-b664-4416-93b7-96ab1e3510cc
< 7.3.12
LOW 3.7 Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11). wordfence
1a182243-b24a-4c46-8b65-6b38d8509a51
< 1.3.9.3
LOW 3.7 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modificatio… wordfence
0fcdfba2-aa19-4d0c-8880-5ee2c0680555
< 3.7.40
LOW 3.7 WordPress Core in versions up to 6.0.3 had a weakness in how Share User Instances were handled. This fix appears to have… wordfence
0c4eb735-46bc-4eed-9d9a-b3bd42d18eed
< 1.9.4.1
LOW 3.7 The Freesoul Deactivate Plugins plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, … wordfence
e86152a6-cd8d-4466-bcc5-830413500e12
< 4.2.1
LOW 3.5 The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request… wordfence
b9e64c54-a78f-454a-a9ee-02f64b6ae83d
< 1.7.5
LOW 3.5 The WP Fastest Cache Premium plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an… wordfence
8746bd3a-6e2b-4ed2-9b21-4ed5a0e58de8
< 3.7.34
LOW 3.5 In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fi… wordfence
77930416-d79b-42bc-8a84-f7f140679a8a
< 2.7.21
LOW 3.5 The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data… wordfence
76af4656-547b-4daf-9078-8ed2b425d1ca
< 3.7.22
LOW 3.5 Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/us… wordfence
5178f7ee-d7e3-4cd1-8cc2-121d217e66fa
< 5.1.3
LOW 3.5 Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before… wordfence
a832cd41-c7be-43b5-bee3-4489170cad79
< 1.6.1
LOW 3.4 Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were discovered in tarteaucitron.js – Cookies… wordfence
a4e542e0-98cc-46af-bedf-a33b133b6de1
< 3.15.8
LOW 3.4 The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.15.… wordfence
06b332de-4f94-47dc-a573-53514adaf5c0
< 3.4.0
LOW 3.4 The affiliate-toolkit – WordPress Affiliate Plugin is vulnerable to Open Redirect in versions up to, and including, 3.… wordfence
← Prev 1586 1587 1588 1589 1590 1591 1592 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top