πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1518 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
46030da6-6d9f-4934-a93c-4cd564510f36
< 7.2.1
MEDIUM 4.3 The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
46030034-9731-4b6d-a3c9-c2dd9a206c46 MEDIUM 4.3 The Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter plugin for WordPress is vulnerable to … wordfence
45e77c74-ba6b-4018-9f97-db393bad6783 MEDIUM 4.3 The Wishlist plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… wordfence
45badd20-1ba8-44be-8a7c-2ce21261e208
< 1.0.7.5
MEDIUM 4.3 The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
45b627f9-e7c6-4bf6-b1c7-d607f3e083f8
< 1.0.4.1
MEDIUM 4.3 The Abandoned Cart Recovery for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
45a7a49c-4fe4-49f0-9399-400116e6606b MEDIUM 4.3 The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
45a14fc2-cc58-4d52-aad5-22c4880ccea1
< 1.26.6
MEDIUM 4.3 The Import and export users and customers plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
459e405a-b676-4797-bf11-339bb382805b MEDIUM 4.3 The AnyComment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
4599b145-cb89-48d4-8581-e1ee7a7bd323
< 3.3.2
MEDIUM 4.3 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification … wordfence
4596378b-90de-4de8-9543-15b45bdee902
< 3.1.8
MEDIUM 4.3 The Vitepos – Point of sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due… wordfence
459384b6-c73d-4e34-81d3-c0586cf50933
< 2.2.5
MEDIUM 4.3 The WP Events Manager plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 2.2.4. … wordfence
45906cc2-74ce-4882-950d-733a94547ab6
< 3.5.6.5
MEDIUM 4.3 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
458d5744-b2c1-4c3d-9b32-76e8174cbf4d
< 1.0.7
MEDIUM 4.3 The ContentMX Content Publisher plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
45883d55-cecd-43b3-a4d7-145f664e784f MEDIUM 4.3 The Pinterest Automatic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
4580c687-5cc9-4b04-b272-0c41260d8db9 MEDIUM 4.3 The Noindex by Path plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
456c13f5-4a8b-4eea-a2a0-f37f8508551b
< 2.4.1
MEDIUM 4.3 The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
4534efd4-0e6b-4784-8f81-4a643f657c66
< 8.1.9
MEDIUM 4.3 The Media Library Folders plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including… wordfence
4528f805-bbf3-4a0f-a06f-879c6e607bfa
< 3.1.0
MEDIUM 4.3 The WooCommerce Product Table Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
450e5cfb-8427-4c50-b1a3-8fceb5c78099
< 2.1.9
MEDIUM 4.3 The Publitio plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
450d4c30-b799-44c9-b60e-a1d701e9055e MEDIUM 4.3 The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwan… wordfence
44f1342a-11b3-4c3f-837f-f68176ded4a9
< 3.2.11
MEDIUM 4.3 The Robo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.… wordfence
44e84fd9-bc83-4780-ab7a-8898a8c5c78a
< 2.4.0
MEDIUM 4.3 The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized use of functionality … wordfence
44e61ac0-f420-4603-a81f-031a22e01927 MEDIUM 4.3 Cross-Site Request Forgery (CSRF) vulnerability in Aftab Muni's Disable Right Click For WP plugin <= 1.1.6 at WordPress. wordfence
44dd7b3f-5892-43e1-acf1-61f66db0b4a3
< 1.5.16
MEDIUM 4.3 The AMP WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.15. Th… wordfence
44dba2ac-3e8f-4544-b568-c72705fd3c0a
< 1.1.0
MEDIUM 4.3 The Z Companion plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
← Prev 1515 1516 1517 1518 1519 1520 1521 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top