πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1509 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4f9a1cfc-5e52-40da-bb9d-8f2b46d37c8c
< 13.7.3
MEDIUM 4.3 The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … wordfence
4f99d8b5-e71d-4b40-8223-f0e53b9dd84f
< 2.1.9
MEDIUM 4.3 The WooCommerce Checkout Field Editor (Checkout Manager) plugin for WordPress is vulnerable to Cross-Site Request Forger… wordfence
4f97bbd7-289a-4d13-b49e-563c17714015
< 2.2.12.1
MEDIUM 4.3 The JetTabs plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
4f954362-9da5-4b40-a7fa-c0c4c5e10efa
< 2.2.0
MEDIUM 4.3 The Hesabfa Accounting plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
4f8fc864-8e09-4dfc-9414-f8d38b393a50 MEDIUM 4.3 The Email Keep plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
4f792f34-a755-441b-90a8-4f2df3332ccb
< 1.5
MEDIUM 4.3 The Community Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
4f730cec-c086-441f-bebb-643aceb1e668
< 5.0.4
MEDIUM 4.3 The Shipmondo – A complete shipping solution for WooCommerce plugin for WordPress is vulnerable to unauthorized access… wordfence
4f6f2a8c-ecd9-482c-a32e-0c3d7a7e4ec4
< 2.0.0
MEDIUM 4.3 The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu… wordfence
4f589e21-7417-4b43-b580-4f1d3c2041f4
< 4.5.4
MEDIUM 4.3 The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check … wordfence
4f530fa1-439f-49c8-850b-96454b9ba7a7 MEDIUM 4.3 The WordPress Testimonials Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
4f481478-5dc9-4b11-ba3e-1942882a9f43
< 11.7.3.1
MEDIUM 4.3 The The7 theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 11.7.3. This … wordfence
4f4635ac-2ce6-4135-8d2b-d03b42860f05
< 3.1.7
MEDIUM 4.3 The Advanced Database Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
4f36e9b9-ef90-4169-ba71-e3b3b29a6a42 MEDIUM 4.3 The Lenix scss compiler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
4f2dc3e7-1e10-4547-8469-726c6747465d MEDIUM 4.3 The Comment Images Reloaded plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability … wordfence
4f2c3819-2247-4ef7-b177-cc98cbf5eae3
< 24.0303
MEDIUM 4.3 The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
4f1932d9-35d3-4d3e-bdbb-c238efda430f
< 1.9.7
MEDIUM 4.3 The Attire Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9… wordfence
4f0d1e8d-bb7f-44ce-a865-8ef15476351e
< 2.0.85
MEDIUM 4.3 The Ads by WPQuads – Adsense Ads, Banner Ads, Popup Ads plugin for WordPress is vulnerable to unauthorized access due … wordfence
4f062ef2-ef94-47c2-8eba-dc7ff6c2537d
< 4.1.6
MEDIUM 4.3 The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
4efc9c47-321a-4635-943f-785ffc34d851
< 2.6.10
MEDIUM 4.3 The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… wordfence
4ef3d4d1-95ce-4180-bb83-afd402094f04
< 4.5.11
MEDIUM 4.3 The WPML plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 4.5.10. This is d… wordfence
4ef3cc5f-c4f9-489b-8fd7-5823ba5ec951 MEDIUM 4.3 The Scroller plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
4edc7ef9-33db-4433-8ef2-cd06089ee8d5
< 1.0.15
MEDIUM 4.3 The Spexo Addons for Elementor – Free Elementor Addons, Widgets and Templates plugin for WordPress is vulnerable to un… wordfence
4ed63724-c21f-4b0e-b595-e824d3519b21
< 1.1.6
MEDIUM 4.3 The HT Portfolio plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.… wordfence
4ece169e-4741-48c5-a7ea-33549e483a4f MEDIUM 4.3 The Indeed API plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.5. T… wordfence
4eca64d7-6e33-4b8e-af37-a3e8bbf2b76f
< 3.9.8
MEDIUM 4.3 The CHP Ads Block Detector plugin for WordPress is vulnerable to unauthorized plugin settings update and reset due to a … wordfence
← Prev 1506 1507 1508 1509 1510 1511 1512 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top