πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1513 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4b2bd577-a4a8-4999-b751-a6f52a12d019 MEDIUM 4.3 The Uper for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
4b1c0ee5-5329-411c-8030-14bec586d74d
< 2.10.5
MEDIUM 4.3 The Customify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.4.… wordfence
4b19657c-3e95-42cf-8d1a-64fa50b3b82b
< 2.3.6
MEDIUM 4.3 The WCMultiShipping plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … wordfence
4b13388b-19f9-4f5c-9599-efd6ccf978c8 MEDIUM 4.3 The Availability Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
4b0b13b4-b604-4514-845e-05a3b8858c66
< 1.4.1
MEDIUM 4.3 The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
4afea729-a7d9-4b38-a0f5-5af2c31bfbb9
< 4.9.9
MEDIUM 4.3 The Spiffy Calendar plugin for WordPress is vulnerable to unauthorized modification of data due insufficient restriction… wordfence
4afb151c-4e6b-4441-a190-becd4fe78019 MEDIUM 4.3 The Joy Of Text Lite – SMS messaging for WordPress. plugin for WordPress is vulnerable to unauthorized access due to a… wordfence
4af2b01b-2dcb-44ae-a764-8ecc5f8caa81
< 4.1.41
MEDIUM 4.3 WordPress Core is vulnerable to Directory Traversal in various versions up to 6.5.5 via the Template Part block. This ma… wordfence
4aec0bf3-82d7-4479-8bd6-941404b6bd03
< 1.7.9
MEDIUM 4.3 The Slideshow Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
4ae41106-c61f-45de-88d8-6dfa2347495c
< 2.0.13
MEDIUM 4.3 The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… wordfence
4ae3ad65-54d7-4ee0-894f-8ffd9fa8ac35
< 2.7.2
MEDIUM 4.3 Cross-site request forgery (CSRF) vulnerability in the WordPress Related Posts plugin before 2.7.2 for WordPress allows … wordfence
4ad16964-3d0a-4769-a167-5ec62486bfe9
< 1.4.7
MEDIUM 4.3 The Educare plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the e… wordfence
4acdf17a-c249-4317-bd4a-1f4b6c66ce15
< 2.0.9
MEDIUM 4.3 The ProSolution WP Client plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
4acb4fda-0217-44b9-a85e-64807eb4a011
< 4.2.2
MEDIUM 4.3 The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to unauthorized Smar Message activation/deacti… wordfence
4aab594d-1901-4f88-874c-204578eebda0 MEDIUM 4.3 The CommentTweets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
4aa589b3-2ad9-4498-8578-1d00736a3b7e MEDIUM 4.3 The Backpack Traveler - Modern Travel Blog WordPress Theme theme for WordPress is vulnerable to Insecure Direct Object R… wordfence
4aa4cb93-7af3-4427-a17f-160b27fcebb8 MEDIUM 4.3 The Coil Web Monetization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
4a87c261-5452-48c9-ab4a-2cf6af0fef56
< 3.8.10
MEDIUM 4.3 The SEO Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.9… wordfence
4a82a3b7-eb05-4f52-84b7-f1a97dddedf9
< 3.6.5
MEDIUM 4.3 The WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, includ… wordfence
4a7ef5a0-f6c8-41e1-bb3b-119a682be69f
< 1.7.1004
MEDIUM 4.3 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up t… wordfence
4a7df25c-00a7-40ec-a851-374543fc549d
< 1.2.49
MEDIUM 4.3 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordP… wordfence
4a7b6fa4-13a5-410a-979e-fbced2a3373b
< 5.1.9.5
MEDIUM 4.3 The Survey Maker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
4a6efab8-04a0-459f-a791-9360c83e5dbe MEDIUM 4.3 The Features plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… wordfence
4a5d59da-dcac-44b4-a697-38eef650c6de
< 1.3.30
MEDIUM 4.3 The Favicon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.29. T… wordfence
4a5c4bef-f871-4e6b-9b6e-85079f1233a2
< 1.2.2
MEDIUM 4.3 The Injection Guard plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the… wordfence
← Prev 1510 1511 1512 1513 1514 1515 1516 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top