ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1089 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
44583cb7-bc32-4e62-8431-f5f1f6baeff2
< 10.0.2
MEDIUM 5.4 The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versio… wordfence
443bae1e-21a0-44b3-bda0-a189f5c69a16 MEDIUM 5.4 Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authent… wordfence
443a4afc-5dfc-499c-8701-249c71215b5a
< 2.73
MEDIUM 5.4 The Timed Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in ver… wordfence
44287d9f-93db-417c-bf88-6785e4ce3a9c
< 4.0.7
MEDIUM 5.4 The MainWP UpdraftPlus Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and inclu… wordfence
43c9b6f2-2b72-4326-8080-f41606c0880c
< 1.5.5
MEDIUM 5.4 The Simple Event Planner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘&custom[add_seg][]… wordfence
43b43802-f301-4748-98b9-eea78a249355
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
4352b2dc-d2a7-4cc9-a44f-1f5be46e2482
< 1.0.22
MEDIUM 5.4 The ALD Dropping and Fulfillment for AliExpress and WooCommerce plugin for WordPress is vulnerable to Cross-Site Request… wordfence
43357daa-4dce-4851-b41b-48d3ffb8a387
< 1.0.0
MEDIUM 5.4 The HTTP Auth plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.3.2. … wordfence
432effd4-5c94-4ef9-bc19-b4eacd082264
< 1.0.7
MEDIUM 5.4 The Accessibility plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
432df51f-2855-4bf2-8be1-77a893e3aa29
< 4.8
MEDIUM 5.4 The WP-Chatbot for Messenger plugin for WordPress is vulnerable to unauthorized access and modification of data due to m… wordfence
431d352b-d79b-4a6b-91f9-95962be3049e
< 3.7.34
MEDIUM 5.4 In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in … wordfence
43100062-c6bd-4d08-a88b-fbcf24f7e605
< 5.3.6
MEDIUM 5.4 The Customer Reviews for WooCommerce plugin contains several AJAX actions that are not protected by capability or nonce … wordfence
42e8129f-dbbd-4dd3-a7a5-c6242c43dfe8 MEDIUM 5.4 The Auto-hyperlink URLs WordPress plugin through 5.4.1 does not set rel="noopener noreferer" on generated links, which c… wordfence
422ae683-dbbe-43ef-b902-ae7570495f21 MEDIUM 5.4 The HomeSweet - Real Estate WordPress Theme is vulnerable to Insecure Direct Object Reference via 'property_id=2769&remo… wordfence
41d03524-7a53-40cd-a3d5-dafea4fc9a33
< 121
MEDIUM 5.4 The Simple URLs plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 120. … wordfence
41b3a62c-9586-4c87-828a-584dfe386a37
< 3.2.49
MEDIUM 5.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ and 'label' p… wordfence
417baa1c-29f0-4fec-8008-5b52359b3328
< 5.9.5
MEDIUM 5.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
4137b8a6-532a-42fb-aa16-7d1de0e2f11f MEDIUM 5.4 The Advanced uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary fi… wordfence
410ae439-dcee-4050-81a9-110a337016e6
< 3.5.4
MEDIUM 5.4 The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) paramet… wordfence
4104f69f-b185-498a-aabf-2126ffb94ab3
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
40ba98a0-2193-4201-8370-34fd438dadb3
< 1.7.4
MEDIUM 5.4 The Custom Related Posts plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missi… wordfence
402bbe9c-cf4d-457c-97ac-149e14ea6f47
< 7.3.0
MEDIUM 5.4 The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This … wordfence
401ea644-bab2-4578-ab1a-7851c2e710ce
< 4.0.8
MEDIUM 5.4 The MainWP Wordfence Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and includ… wordfence
3f6683c7-182a-4cd9-be6e-9832f01c3c71 MEDIUM 5.4 The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php deletegc XSS. wordfence
3f635716-5748-48bf-bbfb-75d302a901e9
< 4.31
MEDIUM 5.4 The CoDesigner plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
← Prev 1086 1087 1088 1089 1090 1091 1092 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top