πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 763 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
52a03c45-1d65-43aa-b30f-13698019e05f
< 5.6.0
MEDIUM 6.3 miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability… wordfence
524a2143-b15f-4edc-98de-dafef4c5bc00
< 3.8.23
MEDIUM 6.3 The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary sho… wordfence
511ce6f6-aea3-4c37-8312-d6e5ff2fdf6f
< 1.4.8
MEDIUM 6.3 The The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via form_preview_shortcode AJAX a… wordfence
501e3c8a-350e-4431-b6a2-012e837320bc
< 3.1.3
MEDIUM 6.3 Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors rela… wordfence
4fb0c069-ea6d-4eff-851e-b41c34b41152
< 1.05
MEDIUM 6.3 Cross-site request forgery (CSRF) vulnerability in the Portfolio plugin before 1.05 for WordPress allows remote attacker… wordfence
4d252639-8cbe-4c62-9218-ebdcbaf98393
< 3.3.3
MEDIUM 6.3 Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPre… wordfence
4c3789d0-6872-4691-94d9-58e1ac303c31
< 7.4.1
MEDIUM 6.3 The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
4aae4571-671a-46d7-b490-6cd0feced0af MEDIUM 6.3 The WP Private Messages plugin for WordPress is vulnerable to SQL Injection via the β€˜id’ parameter in versions up to… wordfence
494d2e69-0759-419a-a603-e8870c157e49
< 3.1.8
MEDIUM 6.3 The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized… wordfence
49008e63-d369-49b8-9dd7-3dff6dbea17c
< 4.2.3
MEDIUM 6.3 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabil… wordfence
46bc15d6-dc1b-40ec-8bb9-5342a4f84372
< 5.3.9
MEDIUM 6.3 The XStore Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several f… wordfence
461cec8c-77e4-4f20-8dff-c4f675dc235f
< 3.11.10
MEDIUM 6.3 The Easy Appointments plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
45a870f4-7ad1-447b-81ea-5d9e9b67b1bb
< 1.9.9
MEDIUM 6.3 The WP Docs plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is… wordfence
43fc47ca-15ca-4817-b1b8-389245725e73
< 3.4
MEDIUM 6.3 The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized access, modification or deletion o… wordfence
413b2b38-44f2-4756-b66d-b6544c7ecaa2
< 1.2.4
MEDIUM 6.3 The Shoppable Images Liteplugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versi… wordfence
3e55591e-c1e9-4667-b04f-4956d2f37d51
< 6.7.1
MEDIUM 6.3 The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
3cd02dbc-6725-4626-844b-df12bad9da37
< 2.16.5
MEDIUM 6.3 The Relevanssi – A Better Search plugin for WordPress is vulnerable to authorization bypass due to missing capability … wordfence
3a1f3fdb-a786-4159-9020-648bc0658268
< 3.0
MEDIUM 6.3 The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=mult… wordfence
39fb0499-9ab4-4a2f-b0db-ece86bcf4d42
< 2.0.2
MEDIUM 6.3 The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request For… wordfence
397f20d8-2400-4403-8543-f57141378012
< 7.3.10
MEDIUM 6.3 The AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin … wordfence
3942bba9-3c3a-47bf-9a53-95376917d6bb
< 5.8.1.1
MEDIUM 6.3 The TheGem theme for WordPress is vulnerable to improper authentication in versions up to 5.8.1.1. This makes it possibl… wordfence
391ef7e0-d4e6-4c2e-b15e-65bdba190b69
< 6.4.1
MEDIUM 6.3 The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability chec… wordfence
39003835-80df-49c7-982a-346bf328565c
< 2.2.2
MEDIUM 6.3 The WPGetAPI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… wordfence
382dcf3d-1290-4e97-b0d6-a4b34461f8a4
< 1.2.4
MEDIUM 6.3 The Plausible Analytics plugin is vulnerable to unauthorized setting changes in versions up to, and including, 1.2.3 due… wordfence
3758db41-a3c5-436a-bb9a-5886f10d1519
< 2.10.0
MEDIUM 6.3 The WCFM Membership plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
← Prev 760 761 762 763 764 765 766 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top