πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1197 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4d0afd4c-b525-48de-a411-c0d974c76fc2
< 2.5.6
MEDIUM 5.3 The WebAuthn Provider for Two Factor plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in all versi… wordfence
4d0a0aa7-7bd9-4883-85b6-b7abf338aa75 MEDIUM 5.3 The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized acc… wordfence
4cee3426-63f4-47c3-9668-64217994752c
< 1.2.0
MEDIUM 5.3 The Magic Export & Import plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… wordfence
4cd27ece-2554-4363-9f3f-161486bfb3ac
< 4.19.0
MEDIUM 5.3 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized acce… wordfence
4cc5c663-d1e3-4656-ac69-0d610eeaf774
< 14.8
MEDIUM 5.3 The VS Contact Form plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 14.7. This ma… wordfence
4cbc0dd4-4dea-4890-95d0-9531a669b95d MEDIUM 5.3 The Frontend File Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
4cb3d2d4-256c-4128-9397-8b9c7be1b9c8 MEDIUM 5.3 The Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
4c7faa73-2d6b-4bf6-9ba3-f511450d6e6e
< 1.9.12
MEDIUM 5.3 The Cart Weight for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
4c7b4361-75ac-4f09-9f69-afb5898cff0c
< 5.2.0
MEDIUM 5.3 The User Registration & Membership plugin for WordPress is vulnerable to Payment Bypass in versions up to, and including… wordfence
4c65a595-b7c6-461f-b08c-d3793c3d84de
< 3.0.2
MEDIUM 5.3 The Builderall for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
4c63154e-9413-47ea-a740-441618266adf
< 3.5.3
MEDIUM 5.3 The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including… wordfence
4c5dd7a4-0e9c-4e1e-8385-2e76b7b9b02e MEDIUM 5.3 The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Sensitive Data Exposure in all versions… wordfence
4c4e1d2c-bb20-40b7-90a3-96df68d083b8
< 1.8.6
MEDIUM 5.3 The Gutenverse plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
4c4cf43f-ea9a-419d-8f62-a7cbec4310da MEDIUM 5.3 The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized access due to … wordfence
4c3aa6e7-9aac-4815-b441-3dbabac9d47d
< 1.3.15
MEDIUM 5.3 The User Registration Stripe plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
4c305546-1548-4b77-a484-d7c51d829792 MEDIUM 5.3 The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … wordfence
4c2ce19e-17b2-4638-9a59-6a6de0370ef8
< 1.0.30
MEDIUM 5.3 The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorize… wordfence
4bf3248a-f235-472c-b751-96ac9838b27f
< 2.8.0
MEDIUM 5.3 The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… wordfence
4bdac6c7-ae50-44e8-aab6-5d8597111d71
< 1.16.8
MEDIUM 5.3 The ERP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in ver… wordfence
4bc58312-ef3d-487b-87fb-9a15a8c6559f
< 14.11
MEDIUM 5.3 The CformsII plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 14.10.1. This is due… wordfence
4bb9f98e-c223-4ee4-a2da-b1a62d995410
< 1.0.11
MEDIUM 5.3 The Connector to CiviCRM with CiviMcRestFace plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
4bb43aad-e3ac-4b32-a3c3-e3b6fce209fe
< 6.1.1
MEDIUM 5.3 The Event Post plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
4bb046c1-a0dd-4d2f-952f-953c5be0a7a2
< 3.0.2
MEDIUM 5.3 The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
4b9abbf1-d9f5-4406-9d0c-bc2f9891d0e8
< 3.1.0
MEDIUM 5.3 The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due … wordfence
4b71a48c-f041-47be-b2e7-6e8b2951e526 MEDIUM 5.3 The HotStar – MultiPurpose Business WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a … wordfence
← Prev 1194 1195 1196 1197 1198 1199 1200 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top