πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 765 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
102bab51-2dc7-4013-8273-21e2ff6cdf79
< 2.6.5
MEDIUM 6.3 The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme – My Sticky… wordfence
10021498-73c8-4767-b059-f282ddc35963
< 1.10.20
MEDIUM 6.3 The Popup by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
0eff89a8-07b7-49fc-b68d-9efd87fcac3c
< 3.0.3
MEDIUM 6.3 The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, wh… wordfence
0e9bac4c-3a07-4a76-b2bd-365aae455086
< 6.10
MEDIUM 6.3 Cross-site request forgery (CSRF) vulnerability in the Easy AdSense Lite plugin before 6.10 for WordPress allows remote … wordfence
0e828fbc-d465-4d69-b7d6-42e2ad87f73d
< 2.3.2
MEDIUM 6.3 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
0e430180-5b89-4d06-b729-d0fdbefa8185
< 1.0.1
MEDIUM 6.3 The MWB Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to… wordfence
0d87a375-81b8-4f81-8fd5-46608c84faca MEDIUM 6.3 The The Embed RSS plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includi… wordfence
0cba362e-c1e3-4840-941f-b8af8469f771
< 3.13.1
MEDIUM 6.3 The Elementor Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of d… wordfence
0a8de5b1-fefc-40b0-8f4d-435e6bd2f452
< 3.0
MEDIUM 6.3 SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to … wordfence
0793a054-b213-4519-bc30-ce835979248b
< 2.4.1
MEDIUM 6.3 The Custom Field Suite plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in th… wordfence
077b3483-ab1c-401d-aa67-c4da5fca90b4
< 4.9
MEDIUM 6.3 The File Manager plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various … wordfence
074e8e37-147d-47ea-93ed-652d7de7be9e
< 5.8.1.1
MEDIUM 6.3 The TheGem theme for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capabil… wordfence
057ded1d-e8b5-4134-ad20-39007096561a
< 2.9.9.5.8
MEDIUM 6.3 The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access du… wordfence
01940eeb-b4a6-450d-b646-84f415ca92c9
< 7.8
MEDIUM 6.3 The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to,… wordfence
0183866d-1eab-4982-b62e-77751c7e738c
< 7.0.5
MEDIUM 6.3 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in a… wordfence
01836c2c-0976-493e-8b13-1c7c702d1d2c
< 3.3.7
MEDIUM 6.3 The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
01486af8-b378-4663-a9c5-167b8580db94
< 2.3.1
MEDIUM 6.3 The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization b… wordfence
9f70f3d2-c267-4802-9a54-4f64c4507dba MEDIUM 6.2 The Urban City theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the do… wordfence
ffffcb92-853e-4aad-b6b8-288443ffd8bc MEDIUM 6.1 The Yummly Rich Recipes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
ffe9bfbd-3672-4162-bb1b-675c7eb9e655
< 2.5
MEDIUM 6.1 The "Konzept - Fullscreen Portfolio WordPress Theme" theme for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
ffe33097-66fc-45f1-bc08-93a2b2234501
< 2.0.4
MEDIUM 6.1 The Bug Library WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the successimportcount parameter fo… wordfence
ffdd9c43-4e6a-4f1b-8ef0-437c545a9a50 MEDIUM 6.1 The PropertyShift plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
ffd889b0-ff2e-469a-bd0b-f009cf773ade
< 3.2.1
MEDIUM 6.1 The WPFront User Role Editor WordPress plugin before 3.2.1 does not sanitise and escape the changes-saved parameter befo… wordfence
ffc2e04f-6e71-4783-bded-7d7782e2e84e
< 1.1.0
MEDIUM 6.1 Custom URL Tracking Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_… wordfence
ffb97fa2-456c-4bc4-a09c-54daa17be3e8
< 4.07
MEDIUM 6.1 The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page requ… wordfence
← Prev 762 763 764 765 766 767 768 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top