πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1514 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4a5787f3-6a16-491a-aa01-6222f275cf0f
< 3.9.5
MEDIUM 4.3 The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
4a3f835e-0aa9-4581-9150-fe5041e0f293
< 4.5.4
MEDIUM 4.3 The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check … wordfence
4a308056-aadc-4fc3-8133-2b05f3d9aabe
< 1.2.6
MEDIUM 4.3 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin fo… wordfence
4a134509-8dc0-41ac-9b5c-5b173a1e3c68
< 1.7.6
MEDIUM 4.3 The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
4a0d7c79-43d1-42e3-b62b-f7c1dce42810 MEDIUM 4.3 The Author Box Plugin With Different Description plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
4a0cffca-94d8-46b8-8b84-57e76a5bfd94
< 1.5.8
MEDIUM 4.3 The Trending/Popular Post Slider and Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery due to miss… wordfence
49f7e35d-e453-4e60-8f73-12891def267a
< 2.23.2
MEDIUM 4.3 The Woocommerce ESTO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
49f1f47d-8fa4-4989-9e89-75c392755f8c MEDIUM 4.3 The Directory Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
49ebff14-ce09-4607-8246-50ae028957f6
< 1.4.11
MEDIUM 4.3 The CP Multi View Event Calendar plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… wordfence
49dbfaf2-c0b0-4852-a97c-001c040ec770 MEDIUM 4.3 The WP-Database-Optimizer-Tools plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
49d54d19-632b-479f-80dd-d66d4285520e
< 4.9.8
MEDIUM 4.3 The Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.9.7… wordfence
49d31bb7-da1b-4c75-997b-4aa7f80de016
< 2.1.0
MEDIUM 4.3 The Web Accessibility with Max Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
49d03254-7399-4a5d-9ce9-7d4736b8b2ee MEDIUM 4.3 The wpCentral plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. … wordfence
49ce8ca1-c1ae-4dda-909e-70c3b6d2b561
< 1.3.8
MEDIUM 4.3 The Forex Calculators plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
49c66f9e-e58c-435b-9bb0-d6b66261e789
< 11.1.5
MEDIUM 4.3 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypa… wordfence
49ba5cfa-c2cc-49ac-b22d-7e36ccca6ac5
< 1.1.3
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
49a33b67-4872-4406-be1c-7c60ea79698b MEDIUM 4.3 The Post Author plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
49a04155-9fa8-45e0-b80b-3836d5271fa7
< 1.1.1
MEDIUM 4.3 The Menu Swapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.… wordfence
49954c72-df0d-46ec-a252-8af84dea41bf
< 4.15.4
MEDIUM 4.3 The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 Thi… wordfence
4987b1b1-0356-4bc0-a4d5-b9a07830c0d4
< 1.1.9
MEDIUM 4.3 The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… wordfence
497960b4-48f3-4a5d-8b69-586da61761f0
< 1.1.8
MEDIUM 4.3 The Blossom Shop theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.7… wordfence
49690143-93c9-4d54-b98c-6f874f818175
< 1.14.5
MEDIUM 4.3 The Addon Elements for Elementor (formerly Elementor Addon Elements) plugin for WordPress is vulnerable to Sensitive Inf… wordfence
496119d8-6908-44ce-951e-ece45500113b MEDIUM 4.3 The RTL Tester plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2. T… wordfence
494c8d80-61e0-4396-93ed-5f9b4d0bf66d
< 2.0.3
MEDIUM 4.3 The Accordion – Add Horizontal / Vertical Accordion in WP plugin for WordPress is vulnerable to Sensitive Information … wordfence
4945931f-764d-45cf-9157-5dddfb264086
< 24.0303
MEDIUM 4.3 The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
← Prev 1511 1512 1513 1514 1515 1516 1517 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top