πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1516 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
48509d43-57bb-452c-b39b-905354a273f3 MEDIUM 4.3 The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecu… wordfence
484ad4ef-9d0d-4dc5-8bb4-d81d0311ebf8
< 4.5.1
MEDIUM 4.3 The Software License Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
481121b2-4ea9-489e-b582-ec8bbf87c902
< 1.8.8
MEDIUM 4.3 The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
480ab377-b979-4e1c-9c7a-cf63d69ad697
< 1.53.2
MEDIUM 4.3 The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the creat… wordfence
4809d513-69e8-4572-9549-9dba9f40cb80
< 1.3.76
MEDIUM 4.3 The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
47e6b084-206b-42d5-9ab0-94ae41edbd20
< 2.2
MEDIUM 4.3 The WP Quick Post Duplicator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
47dccf26-6c8d-4418-a874-c29749bee537 MEDIUM 4.3 The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
47d158a2-2440-4800-b7e7-b4c171bd218c MEDIUM 4.3 The Cartify - WooCommerce Gutenberg WordPress theme for WordPress is vulnerable to unauthorized access due to a missing … wordfence
47c666b1-1ac2-4764-bbee-385ec321a580 MEDIUM 4.3 The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… wordfence
47bc6797-bb18-4555-9561-846d8efaa842
< 3.19.0
MEDIUM 4.3 The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in … wordfence
47adb5fe-534f-48a9-81a3-883e1d2cda7f
< 2.5.20
MEDIUM 4.3 The Search & Filter Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch… wordfence
47906d5e-b77f-4b40-b89e-0bd0ed82b2e5 MEDIUM 4.3 The MashShare – Social Media Share Buttons, Social Share Icons plugin for WordPress is vulnerable to unauthorized acce… wordfence
4782a5cd-bc20-4348-b902-23e5e380b3b8 MEDIUM 4.3 The WP Forum Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
4775ef21-01d6-4c5a-9e3e-f9b6e093fc7f
< 2.0.12
MEDIUM 4.3 The WooCommerce Conversion Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… wordfence
476bc092-c623-4caf-9676-3036d27c4840
< 3.9.9.1
MEDIUM 4.3 The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '… wordfence
476883a8-c258-477b-99d3-f35423d7a312
< 1.1.9
MEDIUM 4.3 The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, an… wordfence
47504481-6116-453a-82c7-617015b1e178
< 3.0.0
MEDIUM 4.3 The Slickstream: Engagement and Conversions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
473eab06-67c8-4143-9d00-eb2866f101c7
< 4.1.8
MEDIUM 4.3 The Church Admin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.… wordfence
4734243a-aa67-4626-b2cf-a1e746f61dc1 MEDIUM 4.3 The Bluestreet theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.3. … wordfence
47060d4c-00c5-4df9-9c0f-65ec4569cf2c MEDIUM 4.3 The Image Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
46ff3005-49aa-4dc8-82cc-f10dc91d252d
< 2.0.9
MEDIUM 4.3 The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to Sensitive … wordfence
46fccb4e-8dd9-414d-bd65-e62acffee18d MEDIUM 4.3 The WP GDPR Compliance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
46f71f7b-7326-47b6-a23a-68a40f5bb56b
< 3.9.4
MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification a… wordfence
46f33846-d70e-41bd-b5e1-7c065a2c201f
< 2.3.7
MEDIUM 4.3 The bunny.net – WordPress CDN Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
46e7ca97-6dd9-4e27-8e69-2e73f9490ea7 MEDIUM 4.3 The WP Hide Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0… wordfence
← Prev 1513 1514 1515 1516 1517 1518 1519 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top