πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1504 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
54e065bf-170d-4f15-879a-fd5fbcb87f79
< 1.3.4
MEDIUM 4.3 The Headline Analyzer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
54dbd2f4-717c-4e01-afe4-c8cceca52650
< 1.5.2
MEDIUM 4.3 The Affiliate Super Assistent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
54db4fef-f834-4026-a7ad-1fffaa3266b5
< 1.0.7
MEDIUM 4.3 The Affiliates Manager Google reCAPTCHA Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
54c63e3d-4588-45e9-ad39-57611aa46aed MEDIUM 4.3 The Logger for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
54bdcae1-28af-4d30-9204-e67b27271042
< 8.0.7
MEDIUM 4.3 The Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.6.… wordfence
54b6a141-eb4c-4cf0-a078-5b3aeda25466 MEDIUM 4.3 The Star Review Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
54b495e8-f641-444d-a3d4-a54bb0836c40
< 8.3.0
MEDIUM 4.3 The WP VR plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a… wordfence
54a08b73-0c8f-4266-90b8-04954b51fe61
< 3.7.4
MEDIUM 4.3 The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
548731d5-078b-45a5-bcc5-9789b41ead44
< 1.8.7
MEDIUM 4.3 The Slider by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
5483980a-3478-4bfa-9571-67b8bd6f3f4d
< 3.29.7
MEDIUM 4.3 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
547d30cd-3b30-44ce-93b5-07ce7a56d0ab
< 3.0.4
MEDIUM 4.3 The MakeStories (for Google Web Stories) plugin for WordPress is vulnerable to unauthorized access of data due to a miss… wordfence
5473ffb2-f9f3-4036-a863-7d1712f5a755
< 1.0.4
MEDIUM 4.3 The Travel Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.3.… wordfence
546f5b08-d4e9-4a19-97d6-2022a0c5c64f
< 3.2.2
MEDIUM 4.3 The Sunshine Photo Cart plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… wordfence
5465eaab-03c0-438a-8553-c1f8b06b82bc
< 2.2.3
MEDIUM 4.3 The Carousel Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
54535bef-23c3-4045-bb37-ba28ae5461b1
< 1.3.2
MEDIUM 4.3 The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includ… wordfence
542b6312-b264-49d5-882a-454427c60c8a
< 1.9.9
MEDIUM 4.3 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
54297bce-e5b7-469e-9c28-1d88e78aacc7
< 4.20.3
MEDIUM 4.3 The Word Balloon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
5427b971-8799-43a4-a60b-717c96e4ee47
< 2.0.0
MEDIUM 4.3 The Image Gallery Block – Create and Display Photo Galleries plugin for WordPress is vulnerable to unauthorized access… wordfence
5424b3ec-37e3-409b-bddc-66b517ecfe7c
< 3.2.3.6
MEDIUM 4.3 The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
541f227f-2e17-4209-b440-fb94892e572f MEDIUM 4.3 The Speed Kit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
54115a9a-dadd-4f18-a139-02ec89f0a571
< 2.8.2
MEDIUM 4.3 The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Inform… wordfence
540de1b8-eb1f-4f9d-b45c-d3d5f11b642d
< 5.7.2
MEDIUM 4.3 The AutomateWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.7.1… wordfence
5402f206-0375-4c47-8a5c-e8ea5742493d
< 1.5.7
MEDIUM 4.3 The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
53fa9be4-a2b3-458c-af6e-d3ada639a622
< 1.12.1
MEDIUM 4.3 The Admin Menu Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
53d5fbcf-7af7-4345-b207-0a3277f78065 MEDIUM 4.3 The WooCommerce Login Redirect plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
← Prev 1501 1502 1503 1504 1505 1506 1507 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top