πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 764 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
35cc980b-9c52-4f0b-aeb2-4afa6efacd8f
< 1.10.6
MEDIUM 6.3 The WP ERP Plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.10.5 due to… wordfence
3541794b-7c8a-42f8-9688-7f3dbbb08e58
< 3.3.3
MEDIUM 6.3 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in al… wordfence
33cf27ba-a01b-4e34-9584-b1d3fc87af34
< 2.1.0
MEDIUM 6.3 The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions … wordfence
2d776d94-8c81-4e88-bae3-946824a75c09
< 2.6.12
MEDIUM 6.3 The bbPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1… wordfence
2d0529df-70be-4559-a760-5537e0fd4d1e
< 3.2
MEDIUM 6.3 Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors rela… wordfence
2b81d7fc-6050-40bb-9416-e8d7d20e8ef8
< 1.14.2.2
MEDIUM 6.3 The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?acti… wordfence
29cc5016-005e-48e8-b929-5064798f24da MEDIUM 6.3 The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provid… wordfence
293070c8-783f-404d-9250-392713703ce4 MEDIUM 6.3 The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability c… wordfence
283fb581-8b61-4008-a5c4-2e1490fab33e
< 4.6.5
MEDIUM 6.3 The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and incl… wordfence
26404b5c-a0f2-4223-be61-1f03873666fb
< 3.2
MEDIUM 6.3 The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… wordfence
245ae6f7-3539-4c91-89f1-29d1e12493b7
< 2.1.2
MEDIUM 6.3 The Abandoned Cart Recovery for WooCommerce by Autonami plugin for WordPress is vulnerable to unauthorized execution of … wordfence
242e99d1-db27-45fa-a90d-5a26c2d1901b
< 2.3.2
MEDIUM 6.3 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to authorization bypass due to a missing c… wordfence
22eda61d-c802-4e9b-a68c-d5ff7d69890c
< 4.1.21
MEDIUM 6.3 The Eventin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.1… wordfence
20de9544-b2fe-470c-a7a4-b662b59d6d31
< 1.5.1.15
MEDIUM 6.3 Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordP… wordfence
1f2d149b-fe63-4fa3-b840-02dc8c5f9323
< 1.3.7
MEDIUM 6.3 The Food Store plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.3.7. This is due to… wordfence
1e1d8afa-0a38-434b-b3d8-04019010ab21
< 1.0.9.2
MEDIUM 6.3 The Transposh WordPress Translation plugin for WordPress is vulnerable to authorization bypass due to a missing capabili… wordfence
1d2b7215-d3a7-4e5a-ae9b-65fecc26dceb
< 8.9.2
MEDIUM 6.3 The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Co… wordfence
1bda01a0-e995-4642-81e3-4a72e6754af6
< 2.0.22
MEDIUM 6.3 The Simple Social Media Share Buttons plugin for WordPress is vulnerable to authorization bypass due to a missing capabi… wordfence
1a2fb050-1a7c-45cc-86c7-02331d47f780
< 2.2.5
MEDIUM 6.3 The WPSchoolPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2… wordfence
19f2fe7c-f702-4db6-9914-2839a62ffdd5
< 5.0
MEDIUM 6.3 The "Discy - Social Questions and Answers WordPress Theme" theme for WordPress is vulnerable to authorization bypass due… wordfence
1814d2ad-73b1-4440-9cd6-7c5c569c4fb2
< 5.0.4
MEDIUM 6.3 The Contact Form 7 plugin for WordPress is vulnerable to authorization bypass due to capability_type mishandling in regi… wordfence
1766727d-ba54-4b46-b362-415c14be027d
< 2.1.5
MEDIUM 6.3 The The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution v… wordfence
14689386-fca5-48a6-9494-4a79b920d5f8
< 3.4.2
MEDIUM 6.3 The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability… wordfence
14376064-13c4-4874-afea-395af2a1933d MEDIUM 6.3 The vSlider Multi Image Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
11d49c89-43be-4e12-86b5-aa7a72a89803
< 1.8.97
MEDIUM 6.3 The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
← Prev 761 762 763 764 765 766 767 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top