πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1511 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4d64a157-8d9c-4c57-b7e2-2d253319da57
< 2.0
MEDIUM 4.3 The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to unauthorized modification of data … wordfence
4d5b1a3d-ce7f-4d5d-b72b-61024d5c5378
< 1.17.1
MEDIUM 4.3 The Thrive Automator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
4d4d0176-3b7d-4de5-95ec-365873e6f13b
< 3.5.5
MEDIUM 4.3 The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a … wordfence
4d3858f5-3f13-400c-acf4-eb3dc3a43308
< 1.1.3
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
4d246a99-fd92-4132-9576-efa065a58f59
< 3.1.5
MEDIUM 4.3 The WP Meteor Page Speed Optimization Topping plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… wordfence
4d23132e-b82e-4129-ab4a-8f0f3721d270 MEDIUM 4.3 The Live Sports Streamthunder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
4d1ef6e3-c502-4099-9099-55058b6ba430
< 1.6.0
MEDIUM 4.3 The Music Player for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
4d114ce7-30af-49a3-a6f7-8445c15a2820 MEDIUM 4.3 The WP Add Active Class To Menu Item plugin for WordPress is vulnerable to Cross-Site Request Forgery in version * -<=1.… wordfence
4cfdbf80-3733-4d5c-9bc6-01e543ee08b1
< 8.1.19
MEDIUM 4.3 The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
4ced42ce-2009-45f6-81c0-ad9e5a05b381 MEDIUM 4.3 The Aspose.Words – Import and Export word documents plugin for WordPress is vulnerable to unauthorized access due to a… wordfence
4ce32dcb-3b7b-433e-9add-512dc2f9f2d8
< 1.3.2
MEDIUM 4.3 The Integration for Contact Form 7 HubSpot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
4cdd4bae-b9ee-4d87-acca-38886f499dcf
< 3.7
MEDIUM 4.3 The Smartsupp – live chat, chatbots, AI and lead generation plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
4cce2842-bd8e-4a83-b83c-66aefe4df4b8
< 3.4.1
MEDIUM 4.3 The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulner… wordfence
4cc29d32-2727-42df-bd42-2caf0f182c0e
< 4.16.13
MEDIUM 4.3 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
4cc27a99-747f-4a80-85f5-b26b6a57d9db
< 0.0.10
MEDIUM 4.3 The Cookie Consent – GDPR & CCPA Cookie Banner & Consent Manager plugin for WordPress is vulnerable to unauthorized ac… wordfence
4cb5d487-0f22-4a34-8558-fe06c19a375b
< 1.0.6
MEDIUM 4.3 The PZ Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
4cb4b5ca-0abc-4b41-bc48-de9740bb13ff
< 1.9
MEDIUM 4.3 The Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets plugin for WordPress is vulnerable to unau… wordfence
4ca43066-fcfb-4e6d-83c4-b6f0108d26ec
< 1.5.5
MEDIUM 4.3 The PDF Generator for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
4c953a46-d2ae-41f7-a940-d23b011d9eca
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
4c8f1c29-b99d-4af0-9cc4-5d6179529ab4
< 4.7.5
MEDIUM 4.3 The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
4c836671-f488-40d9-81b6-e4cd32d0606c MEDIUM 4.3 The Laybuy Payment Extension for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
4c7fe6e7-f776-4fd5-8341-b95237a63d4e
< 1.5.0
MEDIUM 4.3 The Travel Agency plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
4c6e6335-7f18-425a-bb86-7e4fc09dae86
< 1.2.8
MEDIUM 4.3 The Spa and Salon theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.… wordfence
4c659f6d-e02b-42ab-ba02-eb9b00602ad4
< 4.5.2
MEDIUM 4.3 The WP Activity Log Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
4c635405-997e-44ea-8851-7d09051307ad MEDIUM 4.3 The Company Posts for LinkedIn plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in… wordfence
← Prev 1508 1509 1510 1511 1512 1513 1514 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top