πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 758 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f2e36b11-db93-4bac-a9bd-16d2e22efe4d MEDIUM 6.3 The WP-MUI – Mass User Input – Add and Export WP Users Quickly plugin for WordPress is vulnerable to authorization b… wordfence
f167c3c5-df35-456c-a5f1-139cc3c02ffb
< 2.4.49.1
MEDIUM 6.3 The CSS JS Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
f0c7324f-4c22-44e0-8d2a-9b95fd89467d MEDIUM 6.3 The vSlider Multi Image Slider plugin for WordPress is vulnerable to unauthorized access of data, modification of data, … wordfence
efbecb4b-fc41-4719-be5e-af11b47ff683
< 1.1.14
MEDIUM 6.3 The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings. wordfence
ee0eead2-3eab-4a2a-bfe4-c0d8f91dc0a5
< 4.0.52
MEDIUM 6.3 The The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPr… wordfence
ed6e2b9e-3d70-4c07-a779-45164816b89c
< 5.1.2
MEDIUM 6.3 The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. Th… wordfence
ec5e4e3f-df8f-4e07-a6e0-72247b2dd7a7
< 21.7
MEDIUM 6.3 The WooCommerce Multiple Customer Addresses & Shipping plugin for WordPress is vulnerable to Missing Authorization in ve… wordfence
ec0fff2a-602d-441b-89d1-64d609a4abc0
< 3.72
MEDIUM 6.3 The Popup Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 3.71 due t… wordfence
ec03840e-807b-4a9c-87e7-a1560b8b7f5c
< 7.3.0
MEDIUM 6.3 The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable … wordfence
eb99c1a0-a0c3-4a6e-84b1-4ced45015db4
< 2.10.5
MEDIUM 6.3 The Really Simple Facebook Twitter Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in ver… wordfence
e9e256b0-e4e3-4f41-842c-80aa2b80af72
< 3.5.5
MEDIUM 6.3 The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a … wordfence
e999f4c0-03dd-4ea3-9245-b12ffd8da3e2
< 1.7.4
MEDIUM 6.3 The Contact Form & Lead Form Elementor Builder plugin for WordPress is vulnerable to Arbitrary Settings Change in versio… wordfence
e93ad115-1a0b-4d33-b89f-13e39508c9b0
< 7.1.0
MEDIUM 6.3 The Careerfy theme for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, a… wordfence
e92ce899-556f-4a17-8902-1919d485ee15
< 2.0.7
MEDIUM 6.3 Vulnerable versions of the JupiterX Core plugin register an AJAX action jupiterx_conditional_manager which can be used t… wordfence
e8d75eb6-2a9f-4c33-9e15-db7db037b67e
< 1.6.0
MEDIUM 6.3 The Health Check & Troubleshooting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
e702675c-b3ec-458b-a382-cba5c03879c2 MEDIUM 6.3 The OnePress Opt-In Panda plugin for WordPress is vulnerable to unauthorized modification of settings and retrieval of p… wordfence
e64e41a1-ea8e-41b4-911c-672caf0d2df1 MEDIUM 6.3 The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing … wordfence
e35be8ee-81a3-42ce-8304-992bc75663fd
< 2.0.6
MEDIUM 6.3 The wpForo Forum plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… wordfence
e093a923-4b9b-4def-a81b-78584aead5c1
< 1.7.8
MEDIUM 6.3 The WordPress plugin Custom Product Tabs for WooCommerce is vulnerable to unauthenticated options update due to lack of … wordfence
db8bebe2-c50c-4148-b232-04bcd808745e
< 1.2.7
MEDIUM 6.3 The Shapely Companion plugin for WordPress is vulnerable to arbitrary content import due to missing authorization checks… wordfence
da0950ad-4d6c-46fe-83c9-c14653fe9f1f MEDIUM 6.3 The Backup Scheduler plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev… wordfence
d946d4b5-bed7-4808-b133-783b2dcd7992
< 6.6.1
MEDIUM 6.3 The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions… wordfence
d937cacb-eb80-4c7c-9105-4ac4bd5c48cd
< 1.0.2
MEDIUM 6.3 The Category Icon plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in versions up to, and inclu… wordfence
d7d94443-3ab2-4d89-a580-2e9697d28cd7
< 3.5.2
MEDIUM 6.3 WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to byp… wordfence
d7b33199-d254-4d0c-88d0-ad2f7515d747 MEDIUM 6.3 The Kingkong Board plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on one of… wordfence
← Prev 755 756 757 758 759 760 761 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top