πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1492 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
62559fd6-a338-4f0f-ab1a-33fffbdc687e
< 1.6.8
MEDIUM 4.3 The WordPress RSS Feed Retriever plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
624a3174-03fa-4a8e-9c02-5e24add92392
< 2309
MEDIUM 4.3 The Table of Contents Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
62456419-4814-4130-ae3b-302e82f0d91d
< 6.0.3
MEDIUM 4.3 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery… wordfence
623decc5-bdb7-42c9-8531-8004ddc16682
< 1.1.8
MEDIUM 4.3 The WP Plugin Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
623b139e-c5a1-4d2e-b05c-72707f421ef8
< 4.2.2
MEDIUM 4.3 The Smash Balloon Social Post Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
622ee6c8-7739-44ae-b88f-63a93c0a9b20 MEDIUM 4.3 The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.… wordfence
622676ee-7cdc-414e-9dcc-e4b74b512430
< 3.6.4
MEDIUM 4.3 The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
621f85da-8688-46ab-ac32-56036bddf674 MEDIUM 4.3 The Business Roy theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
6200d57b-a62c-434f-a194-9199a1e39304
< 1.1.4
MEDIUM 4.3 The HivePress Claim Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
61d8cbab-c83a-46d9-a730-084f4a2d68df
< 3.6.1
MEDIUM 4.3 The Simple Sitemap – Create a Responsive HTML Sitemap plugin for WordPress is vulnerable to unauthorized access due to… wordfence
61d56713-59af-4ad9-8744-6c6a5e5fe213 MEDIUM 4.3 The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
61d32d2e-1ca0-4a45-8c4d-b6584c2e7c9e
< 1.0.8.4
MEDIUM 4.3 The Permalink Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
61ccba6d-ac82-4ee1-8463-02e2ad5681ab MEDIUM 4.3 The Smart Hashtags [#hashtagger] plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
61a050bd-deaa-4115-baa5-f63790816450
< 2.0.0
MEDIUM 4.3 The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to unauthorized access due to a mi… wordfence
61808624-b2c7-4e86-b5a1-56f32fca9eaa MEDIUM 4.3 The WP-dTree plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.5. T… wordfence
6164b272-aa12-4ee3-a73a-64882ff5a899 MEDIUM 4.3 The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
6150fd60-069f-4ba6-8f0c-773039eaaec6
< 1.6.0
MEDIUM 4.3 The Snap Pixel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.8.… wordfence
613fc64a-1206-4a11-b945-216068b9339a
< 1.42.1
MEDIUM 4.3 The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnera… wordfence
613b2ef8-6749-42a2-a978-c96464ef7470
< 2.2
MEDIUM 4.3 The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missin… wordfence
6125a8e6-4c87-4136-ba39-c3a089948733 MEDIUM 4.3 The CPT Shortcode Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
6125a734-c185-4a97-a4fe-a739aa20de13
< 5.0.5
MEDIUM 4.3 The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
611b369d-3ef0-4f03-a9c0-9ef4f4ffae43 MEDIUM 4.3 The Direct Payments WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i… wordfence
611af50f-7f60-4c09-be64-3f2705e06206
< 6.3.0.3
MEDIUM 4.3 The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
61105f6a-1bd7-415d-9481-a1c2c310f778
< 1.8
MEDIUM 4.3 The WP Duplicate Page plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, … wordfence
60feea0c-046e-469f-a964-98c9b83652c2 MEDIUM 4.3 The Custom Post Status plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
← Prev 1489 1490 1491 1492 1493 1494 1495 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top