πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1590 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fd97fba9-513b-46e1-9613-2f64c4272f34
< 1.1.9.5
LOW 3.3 The Block Referer Spam plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
e9f0689d-aa35-4dfb-b264-5d7378ab1a54
< 5.3.5
LOW 3.3 The iThemes Security plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.3.4 … wordfence
e54d5ab2-40ba-4ad8-9a77-44aba37f0283
< 3.3.3
LOW 3.3 The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for Word… wordfence
e2b9b6f4-6ee7-498d-9693-a5ae5f7f4719 LOW 3.3 The Baidu Tongji generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi… wordfence
9f770bc3-8ccc-4160-9e79-e1c0dee42b73
< 2.3.9
LOW 3.3 The WooCommerce Shipping Label plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all ver… wordfence
6d0fcd82-6d4a-454f-8056-a896e8d41d00
< 7.5.0
LOW 3.3 The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versio… wordfence
5b91ad8b-79ec-4ef7-bb39-edb06309da5e
< 2.6.2
LOW 3.3 The authLdap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions up … wordfence
598e38d7-b5a9-43c1-b908-dab8bbe24115 LOW 3.3 The breadcrumb simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions u… wordfence
077ec165-edd3-4c2c-b1ea-01ca5b80f779 LOW 3.3 The UTM Tracker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings parameter in versio… wordfence
fb0b2e1c-52f2-4f33-9011-e29fd042cf2c
< 10.30.4
LOW 3.1 The Salon Booking System – Free Version plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… wordfence
e13df52d-17dc-471a-886c-f5a28e2d067e LOW 3.1 The Envo Multipurpose theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
da550fd7-3c1a-4b07-afc0-2366e0f5cccd LOW 3.1 The WP Like Button plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
d900584c-0f58-4abc-92ff-841f898d02fc
< 3.3.18
LOW 3.1 The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL I… wordfence
d1213431-a2a7-434a-b479-ac65fbc84820
< 1.3.1
LOW 3.1 The Disable Comments & Delete All Comments plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
be0ab40f-cff7-48bd-8dae-cc50af047151
< 2.6.7
LOW 3.1 The My Sticky Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
b97e41a7-dd0a-41cf-ba74-84b117192088
< 3.13.3
LOW 3.1 The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
ad003d57-a573-473e-80a9-5bf60d42a707
< 1.5.4
LOW 3.1 The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to unauthorizedmodification of data due to … wordfence
74089b16-76fa-4654-9007-3f0c2e894894
< 4.1.5
LOW 3.1 The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based … wordfence
6ae78330-c07a-4ebc-9bb6-2aabeb0c8526 LOW 3.1 The Viral Loops WP Integration plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
58337bbc-ba10-4876-b91c-78657afc67d1
< 3.8.1
LOW 3.1 The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, a… wordfence
52d1f9a3-243e-4e2c-a752-f40b6d275121
< 5.16.1
LOW 3.1 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to invalid l… wordfence
3c59d95a-b7f1-4a04-bbf4-bab2c42d6d75
< 4.10.36
LOW 3.1 The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in a… wordfence
22f98afa-eb14-4326-9971-49092c711249 LOW 3.1 The WPFavicon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… wordfence
1a4321d5-b472-4571-8dc1-96419b59c6c7
< 7.6.3
LOW 3.1 The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
14ccd915-a513-45a4-84d3-b2b1fb893f1c
< 4.15.23
LOW 3.1 The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
← Prev 1587 1588 1589 1590 1591 1592 1593 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top