πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1517 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
46df438c-abff-4cf3-a732-02e0b3196bac
< 1.0.2
MEDIUM 4.3 The ACF On-The-Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
46db2123-d33a-4093-8254-32ff8ff347a3
< 1.3.6
MEDIUM 4.3 The Nelio Popups plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
46c4b7f7-e3e6-46b8-b959-07775db8bb6c MEDIUM 4.3 The WP Gallery Metabox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
46bff42e-d2f6-4221-9920-0fc993a9e939
< 0.8.3
MEDIUM 4.3 The Anthologize plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0… wordfence
46ba9993-4504-4c14-93ce-0ae49f31955f MEDIUM 4.3 The MapIt plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
46abc856-3138-4079-8415-6bb295f33b1b MEDIUM 4.3 The WorkScout-Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
46aa3df1-d6ef-4614-b1cc-a4c9baa8d1c0
< 4.2.1
MEDIUM 4.3 The Side Menu Lite – add sticky fixed buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all … wordfence
46a9475b-f738-47d5-b6fa-daf331e0edf4 MEDIUM 4.3 The AnyWhere Elementor Pro theme for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
4699a9d7-4b72-4266-90be-1407e7d5b1eb
< 2.2.0
MEDIUM 4.3 The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
4695a394-66e3-4ce6-98cd-e169c6495e6a
< 1.0.8
MEDIUM 4.3 The SwiftXR (3D/AR/VR) Viewer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
46951d8d-f8f1-4fb5-b02a-1a19edd154e6
< 5.0.0
MEDIUM 4.3 The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
46903b3f-4041-4d1d-bf49-fb8bd2165c66 MEDIUM 4.3 The Enhanced Blocks – Page Builder Blocks for Gutenberg plugin for WordPress is vulnerable to unauthorized access due … wordfence
46901f22-3a43-42a0-8207-cb2280311335 MEDIUM 4.3 The Revision Manager TMC plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
4680ff56-43b9-47d1-8e28-1f6ad9038417
< 2.4.11.2
MEDIUM 4.3 The JetMenu plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2… wordfence
467f369f-1c7a-4b05-8901-d2850db86a33 MEDIUM 4.3 The Simple Photoswipe plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
467ede83-1ce3-41f2-bc2d-3b0e7a10442f
< 3.0.5
MEDIUM 4.3 The GS Variation Swatches for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to… wordfence
467b2aeb-e116-4266-9f05-1e3322b84229
< 3.2.4
MEDIUM 4.3 The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
464b35bb-d782-477a-8059-c52418c78f22 MEDIUM 4.3 The Academy LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3… wordfence
4648c4f2-47e3-4a95-9e93-fd8246863425
< 4.0.5
MEDIUM 4.3 The MainWP Matomo Extension for WordPress is vulnerable to Cross-Site Request Forgery due to missing or incorrect nonce … wordfence
463fdbde-1d98-4f52-b835-cba1ae567f4f
< 3.0.5
MEDIUM 4.3 The A2 Optimized WP plugin for WordPress is vulnerable to Cross Site Request Forgery due to missing nonce validation on … wordfence
463181ae-1355-4aaf-bd8d-3194d72e0dfc MEDIUM 4.3 The Compact Admin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
4616b609-e8dc-4004-a5b7-2de3e83719be
< 5.2.0
MEDIUM 4.3 The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vu… wordfence
46126f88-416a-4430-8596-12f72cd2c1e7
< 5.6.12
MEDIUM 4.3 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… wordfence
461211c9-951e-4ccd-abf5-84941290a6a5
< 1.0.24
MEDIUM 4.3 The SureTriggers plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… wordfence
460b5388-4862-475d-9557-f8da2d5a84f7
< 1.6.3
MEDIUM 4.3 The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user… wordfence
← Prev 1514 1515 1516 1517 1518 1519 1520 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top