πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1512 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4c611fa0-28ef-4425-8614-fb61e250e625
< 5.9.8.2
MEDIUM 4.3 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message del… wordfence
4c5dc3d9-cb4c-4ae1-b048-c7eea59cb229
< 2.4.2
MEDIUM 4.3 The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
4c5d56ba-8f4f-4596-80e6-0f9194749117
< 5.0
MEDIUM 4.3 The SKT Page Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
4c51613d-8856-4988-85f0-6405b08bc1e0
< 1.1.0
MEDIUM 4.3 The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
4c44e858-7028-495e-b6c7-8b7712e00eaf
< 1.3.64
MEDIUM 4.3 The Contact Form Email plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
4c332ba8-282e-484e-9ee2-a91c9255bad0
< 1.3.72
MEDIUM 4.3 The Appointment Hour Booking plugin for WordPress is vulnerable to authorization bypass due to a missing capability chec… wordfence
4c32a5f5-65f1-44d0-b133-0a304131b1f7
< 1.8.4
MEDIUM 4.3 The Magazine Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
4c306428-8880-483f-be3a-6f6b87e55eef
< 1.6.2
MEDIUM 4.3 The Zippy plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.6.1 v… wordfence
4c2ce765-018a-4292-b150-7905723d1335
< 2.5.7
MEDIUM 4.3 The GamiPress plugin for WordPress is vulnerable to unauthorized modification of user data due to a missing capability c… wordfence
4c1de8e5-e66b-40ff-a73f-334067146d11 MEDIUM 4.3 The Comparimager for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
4c0cbf44-f6b4-408d-9a96-98f45d890822
< 1.1.1
MEDIUM 4.3 The Laposta Signup Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
4c046e0c-32d2-47d1-9890-d05d69217161 MEDIUM 4.3 The Custom Product List Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
4bf4101e-af05-4a26-b479-51d08240024d
< 1.5.5
MEDIUM 4.3 The Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including,… wordfence
4bd464b8-b64e-4e42-a32f-57f4d512468b
< 3.8
MEDIUM 4.3 The HR Management Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
4bc4e54e-6520-48d1-b39e-9493c20d4142
< 1.5.55
MEDIUM 4.3 The Query Wrangler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
4bc4a765-719e-4e99-b7f3-d255e4c019f5
< 2.6
MEDIUM 4.3 The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin … wordfence
4bc23291-1b73-4e92-83ba-0c7f455ac126 MEDIUM 4.3 The Moderate Selected Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
4bbf55eb-7738-4c52-ac9d-a67d159e56cf
< 1.4.6
MEDIUM 4.3 The Keybase.io Verification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
4bb10817-50e6-493a-82e9-92b122ddce06
< 3.2.4
MEDIUM 4.3 The New User Approve plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
4baf39fd-4191-47eb-9b37-cdf290d6345b MEDIUM 4.3 The Ultimate Taxonomy Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
4babd5e9-dfd6-4e6a-a517-6ce4f4d146f6
< 2.2.0
MEDIUM 4.3 The WP Job Manager - Resume Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
4ba3c70a-967f-4dc9-aaac-d13b11eb4711
< 1.3.6
MEDIUM 4.3 Multiple themes for WordPress by themedropbox are vulnerable to unauthorized modification of data due to a missing capab… wordfence
4b6b8b89-13a4-4158-9471-8af86aec0454
< 4.3.1
MEDIUM 4.3 The GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools plugin for WordPress is vulnerable to unau… wordfence
4b6acdeb-8cdf-4526-9772-7dc782726d23
< 2.5.4
MEDIUM 4.3 The WP Performance Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
4b5fbf2c-1231-482f-b5a5-819f31da3524 MEDIUM 4.3 The Fast & Fancy Filter – 3F plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and in… wordfence
← Prev 1509 1510 1511 1512 1513 1514 1515 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top