πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 762 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
74d222b9-22e9-485d-8111-d3bee505b200
< 2.7.0
MEDIUM 6.3 Several WordPress plugins by Wbcom Designs were vulnerable to arbitrary plugin installation, activation and deactivation… wordfence
72bdc81e-1a9d-4dd8-93a5-fb1026d6a2d9
< 27.1.2
MEDIUM 6.3 The Betheme theme for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check … wordfence
6efc3120-4eb0-4816-85ff-afe0aa8adbf0
< 5.0
MEDIUM 6.3 The NebulaX Theme plugin for WordPress is vulnerable to SQL Injection via the nebula_send_to_hubspot() function in all v… wordfence
6ebc1b85-4682-4467-b17c-9a35cc3f0f15
< 5.3.0
MEDIUM 6.3 The WP Easycart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.6… wordfence
6e15d285-aa1d-461d-bdc2-642e7ccd789b
< 3.4.7
MEDIUM 6.3 The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is … wordfence
6d700580-1374-4a17-a6b3-59ba1d063030
< 3.1.23
MEDIUM 6.3 The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary asset manager usage in versions before 3.… wordfence
6aae5b1d-9b84-4628-b0b6-7b39054e08a0
< 4.1.2
MEDIUM 6.3 The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to… wordfence
6aa2d172-73b6-487d-ae65-0920f915e750
< 3.3.10
MEDIUM 6.3 The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
67021dde-a21c-4281-b4f2-acc840efcc69
< 2.7.2
MEDIUM 6.3 The JS Help Desk plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unkn… wordfence
64f51991-f767-4f7b-94e7-68c0e2214849
< 3.0.6
MEDIUM 6.3 wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allow… wordfence
64eb3d67-7056-4a03-ba3b-a04c2e96648d
< 3.3.9
MEDIUM 6.3 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthor… wordfence
644624d8-c193-4ee6-bc82-7ccda5d7f2ac
< 4.7.0
MEDIUM 6.3 The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin … wordfence
5fd470bb-d791-45dc-a743-6f03fc75f00c
< 1.2.1
MEDIUM 6.3 The Editorialmag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
5fbb2dcf-38b8-4ef1-bfea-bf5872cc7e37
< 2.1.4.3
MEDIUM 6.3 The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_sh… wordfence
5f9cf9c5-d836-4414-a53f-adee2784bd96
< 11.16
MEDIUM 6.3 The Media from FTP plugin for WordPress is vulnerable to improper privilege management due to an insufficient capability… wordfence
5df8983e-16c9-4a23-9bf4-331d70384e74
< 5.3.5
MEDIUM 6.3 Cross-site request forgery (CSRF) vulnerability in he Digg Digg plugin before 5.3.5 for WordPress allows remote attacker… wordfence
5dec045a-b87c-4db5-960e-8888e410a950
< 3.1
MEDIUM 6.3 Cross-site request forgery (CSRF) vulnerability in the Login With Ajax plugin before 3.1 for WordPress allows remote att… wordfence
5d635669-ee85-4fb5-8238-3edb3bbb8fb4
< 2.0.16
MEDIUM 6.3 The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due improper capability mappi… wordfence
5c2cc9a3-cd20-4c9e-baa4-1aea69f84331
< 3.5.0
MEDIUM 6.3 The WCFM Marketplace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
59b09f36-79e8-4f14-b970-a7994d193782
< 2.2.0
MEDIUM 6.3 The WooCommerce Warranty Requests plugin for WordPress is vulnerable to unauthorized use of functionality due to a missi… wordfence
56f9d46f-5c21-4e8e-8e77-c96c4a0562d1
< 1.9.92
MEDIUM 6.3 The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions. wordfence
5681101f-13c3-4fde-bbde-554810bcbe4e
< 4.1.6
MEDIUM 6.3 The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing… wordfence
55a942b7-5d3e-4ddf-8bc3-61ff90a7fdbd
< 2.1.6
MEDIUM 6.3 The All in One SEO plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… wordfence
557172d0-33ad-427a-b575-df529e2aaab0
< 2.6.11
MEDIUM 6.3 Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 fo… wordfence
53199f3c-80d1-4c4e-93ef-8a234ba8ba85
< 9.7.5
MEDIUM 6.3 The Quick Event Manager plugin for WordPress is vulnerable to authorization bypass due to missing authorization checks o… wordfence
← Prev 759 760 761 762 763 764 765 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top