πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 761 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9fd38e86-6448-47fd-a8a7-f571158e3599
< 2.9.14
MEDIUM 6.3 The Sunshine Photo Cart plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on … wordfence
9ea2964f-9e3a-450b-9724-5a520c73d306
< 0.9.97.20
MEDIUM 6.3 TheAMP for WP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ampfor… wordfence
9e9823e6-bcd4-4c1e-bf86-caf472748b12
< 2.3.4
MEDIUM 6.3 In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could… wordfence
9d49e28b-8b5e-4c67-a36d-c78ee33ffc6e
< 1.5.66
MEDIUM 6.3 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to unauthorize… wordfence
9764d402-b8a2-43d5-882a-bc3886078b7f
< 11.17
MEDIUM 6.3 The Media from FTP plugin for WordPress is vulnerable to improper privilege management due to an insufficient capability… wordfence
962af7eb-b2eb-4190-bf0d-cb05cb28f10b
< 2.7.8
MEDIUM 6.3 The "JS Help Desk – Best Help Desk & Support Plugin" plugin for WordPress is vulnerable to Insecure Direct Object Refe… wordfence
9251afbb-1a6d-40c6-b62e-a8866742f669
< 12.1.21
MEDIUM 6.3 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized access/modification or loss of data du… wordfence
9071acdf-8d40-4e8b-8d1f-be2cabf3d66e
< 4.900
MEDIUM 6.3 The WPLMS theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 4.900. This is due to missi… wordfence
8f9ee168-82b1-4d13-a84e-379f16dcb283
< 1.7.2
MEDIUM 6.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
8eee3809-133e-4fd9-ad49-cc6fe3822457
< 1.0.3
MEDIUM 6.3 The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu… wordfence
8b32c517-ef6b-4cc9-8316-6289676d8222
< 3.8.6
MEDIUM 6.3 The WooCommerce Ship to Multiple Addresses plugin for WordPress is vulnerable to unauthorized use of functionality due t… wordfence
89dab433-91e9-4500-ab40-f4b500e66983
< 6.11
MEDIUM 6.3 The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized access and modif… wordfence
893500ba-cc16-4429-bbe1-725aa65589c9
< 3.1.2.1
MEDIUM 6.3 Multiple plugins by Crocoblock for WordPress are vulnerable to unauthorized access due to a missing capability check on … wordfence
88d16ce2-a1cf-4402-b140-3cab17f8c638
< 2.4.1.9
MEDIUM 6.3 The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
88907f28-7b1d-4a5a-b846-67dfd21d6488
< 4.0.23
MEDIUM 6.3 The ARMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.22. … wordfence
87e3d9bc-a14c-4134-91ed-9de5177942ca
< 3.1.6
MEDIUM 6.3 The Templately plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
85af2186-0807-4926-9285-f8ac93f76b93
< 4.9.1
MEDIUM 6.3 Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an… wordfence
7ffba592-6d0d-408f-89fa-079066750b0a MEDIUM 6.3 The Waiting: One-click countdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
7e697e7f-8d5b-4a9f-9148-f2dc5fb1ba38
< 1.4.4.2
MEDIUM 6.3 The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to authorization bypass in versio… wordfence
7bfabeb4-c57d-412a-b27b-a6387d30081f
< 1.8.2
MEDIUM 6.3 The HappyFiles Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
7ae1d155-deb4-4847-858b-37b5cd9ac1c5
< 1.08
MEDIUM 6.3 The FormBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.08. This is due to… wordfence
7a5da306-c798-4f2b-8875-8ae54c83ccd8 MEDIUM 6.3 The radSLIDE plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
79b5883b-a3be-497e-b911-7dc39e7fb418
< 2.9.61
MEDIUM 6.3 The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
798b57ad-0922-435c-8b4d-8a96b388b314
< 6.6.0
MEDIUM 6.3 The WCFM Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
75f0bc5a-f588-4aeb-9e55-72e180d39ddf
< 1.0.22
MEDIUM 6.3 The ALD Dropping and Fulfillment for AliExpress and WooCommerce plugin for WordPress is vulnerable to unauthorized acces… wordfence
← Prev 758 759 760 761 762 763 764 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top