πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1510 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4ebc8d0d-04b6-49a0-96c1-7c6d930009d8 MEDIUM 4.3 The Read more By Adam plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check … wordfence
4eb4400d-d629-4c88-9ec5-06da9089f6d1
< 6.21
MEDIUM 4.3 The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
4e8b8689-ab6a-426b-9aba-4fa14c455ff1
< 1.5.39
MEDIUM 4.3 The Page Builder: Live Composer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… wordfence
4e860293-0dfb-444f-a103-33942d9ff75c
< 1.15.2
MEDIUM 4.3 The MultiParcels Shipping For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
4e81e947-4892-4028-8a09-6a048bf6a572
< 0.9.5
MEDIUM 4.3 The POEditor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.9.4. T… wordfence
4e77168e-079e-4c48-9c3a-cb8bfb3d3e53
< 3.8.3
MEDIUM 4.3 The Academy LMS plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 3.8.2. This … wordfence
4e6e8f68-6977-478a-b62e-0ec9385eb2af
< 4.1.7
MEDIUM 4.3 The Snippet Shortcodes plugin for WordPress is vulnerable to unauthorized Shortcode Deletion due to missing authorizatio… wordfence
4e6a896c-9cca-4e4d-b26d-0103a8b39bf7
< 2.6.94
MEDIUM 4.3 The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to unauthorized modif… wordfence
4e62f27b-c6b0-48ed-bfd7-a1893552eb3e
< 6.5.1.2
MEDIUM 4.3 The Quiz Maker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
4e413262-b28e-4650-a200-67285a45670f MEDIUM 4.3 The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to Sensitive Information E… wordfence
4e26f5a0-dd6b-461e-9541-4ae504398544
< 2.9.6
MEDIUM 4.3 The IP2Location Variables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
4e240c06-cc35-4f26-ae55-4dce60e5bec3
< 4.0
MEDIUM 4.3 The Telegram Bot & Channel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
4e190cf2-f968-4e81-af31-bfc67815772c MEDIUM 4.3 The Ninja Forms File Uploads Extension plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
4e1299dc-75a6-4c77-bb92-cb31eea3ab05 MEDIUM 4.3 The 6Storage Rentals plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
4e076c10-7b83-4016-ae31-ee486178a988 MEDIUM 4.3 The File Provider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
4e03b0b9-861d-4909-8608-6378cd0b9176
< 3.9.2
MEDIUM 4.3 The Hummingbird plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.1… wordfence
4dec91d7-19cf-480d-871c-427cd1e691a6
< 6.1.5
MEDIUM 4.3 The Awesome Support plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
4de0d05f-2f51-4fea-9520-ff07a882d95e
< 1.3.9
MEDIUM 4.3 The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve… wordfence
4da14dd1-1dbe-4f2e-980f-3f38a0a33564
< 1.2.18
MEDIUM 4.3 The Search & Filter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
4da012dc-7e58-479a-813e-762eb28297bf
< 4.1.6
MEDIUM 4.3 The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the w… wordfence
4d936a48-b300-4a41-8d28-ba34cb3c5cb7
< 7.0.0
MEDIUM 4.3 The WP Shortcodes Plugin β€” Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference … wordfence
4d8aee12-84c2-4efe-b505-c014029ca0e9 MEDIUM 4.3 The W3Counter Free Real-Time Web Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
4d7f2cea-f132-4881-9632-ee07a7b9d6b8
< 8.1.0
MEDIUM 4.3 The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
4d7b8c5f-3e3d-4ccc-8598-fcb4503c25ea
< 0.1.2
MEDIUM 4.3 The Better Business Reviews – Trustpilot WordPress Plugin plugin for WordPress is vulnerable to unauthorized access du… wordfence
4d740ba8-4877-4b27-a1cb-26095f851ea6
< 1.3.3
MEDIUM 4.3 The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Improper Authorization leading to Sensitive Post Me… wordfence
← Prev 1507 1508 1509 1510 1511 1512 1513 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top