πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1515 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
49438dc5-3728-4aa0-a7b0-ed6dd26fa094
< 2.1.17
MEDIUM 4.3 The Solace theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
4942de17-d141-4a6c-885e-75f540fe21b6
< 2.10
MEDIUM 4.3 The Add Shortcodes Actions And Filters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
494168ab-83d1-4a26-a61d-a02509147890
< 2.22.6
MEDIUM 4.3 The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerabl… wordfence
49405ba1-b0fd-429b-a30a-95c8d3f26545
< 1.0.2
MEDIUM 4.3 The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
4938c1be-2356-4a9c-9795-108a2d5a6cc7
< 1.4.5
MEDIUM 4.3 The Remove Add to Cart WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
49364a21-775a-4de0-84f8-e62aa1a5fefd MEDIUM 4.3 The Lucky Draw Contests plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
492daa1b-e508-40a0-ad4f-1f1d6469d68f MEDIUM 4.3 The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for Wo… wordfence
492a2a6f-78e9-4401-a0a7-b7c1c8349efa MEDIUM 4.3 The Simple Keyword to Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
49275353-4f8a-4110-aaa1-1c7612fa3ce5
< 1.13.63
MEDIUM 4.3 The Product Slider, Product Grid, Product Masonry plugin for WordPress is vulnerable to Insecure Direct Object Reference… wordfence
490b4ee5-dd99-42af-94af-b45cea27b287
< 2.7.6
MEDIUM 4.3 The NPS computy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
49018b4b-2833-4ced-b36a-ebe69c5cb096 MEDIUM 4.3 The Smooth Scroll Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
48fefbd5-d872-4f47-8696-d73fbc9133ed MEDIUM 4.3 The Custom Post Type plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
48f5a44d-d01f-4c41-98da-7c1f6c65c254
< 2.2.1
MEDIUM 4.3 The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on th… wordfence
48f39d6c-621b-4c78-9459-68bb67a94f57
< 4.9.0.8
MEDIUM 4.3 The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes. wordfence
48df36b8-be32-4fe0-8a5d-d750ee499d62
< 5.4.0
MEDIUM 4.3 The EAN Barcode Generator for WooCommerce: UPC, ISBN & GTIN Inventory plugin for WordPress is vulnerable to unauthorized… wordfence
48d6d4c1-cc87-4c2c-9fbb-90af62f576aa MEDIUM 4.3 The Visual Sound plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
48cb5d7b-afbc-4387-ad32-13d2fcb19061
< 2.3.2
MEDIUM 4.3 The Debug Log Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
48be0157-5eb9-4e06-b406-0af659de034b
< 3.1.3
MEDIUM 4.3 The TS Webfonts for SAKURA plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
48aa5be8-a5d9-4f5e-ba30-d6afb3f0fee0
< 1.1.0
MEDIUM 4.3 The Viral Mag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… wordfence
488e26e2-d4d7-4036-a672-53c2d4c9d39b
< 1.7.2
MEDIUM 4.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
488567cd-b296-402f-9056-667b061950da MEDIUM 4.3 The WP Logs Book plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
487e23c9-9100-4240-8992-c4c85930c4a6
< 3.2.4
MEDIUM 4.3 The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPre… wordfence
487a131e-4911-42d6-bfd7-fc697c89552d
< 4.5.4
MEDIUM 4.3 The BizPrint – Print WooCommerce Order Receipts, Invoices, Labels & More. plugin for WordPress is vulnerable to Cross-… wordfence
486b6a75-d101-4f3a-8436-6c23dd0ff200
< 3.23.0
MEDIUM 4.3 The My YouTube Channel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on t… wordfence
48583297-59db-48ec-8551-d6b37ac02197
< 3.3.5
MEDIUM 4.3 The JupiterX Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on multipl… wordfence
← Prev 1512 1513 1514 1515 1516 1517 1518 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top