πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1519 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
44c14dca-19df-4f83-80bf-6ea0ea261e28
< 6.4.19
MEDIUM 4.3 The Business Directory plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… wordfence
44bca8c2-1591-484c-ac40-8c968d5d1cad MEDIUM 4.3 The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
44b62b99-99eb-424b-a04a-9bbacf5fbbaa
< 20240307
MEDIUM 4.3 The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
44b02690-462a-458b-88c9-89acc9c209cb
< 3.0.2
MEDIUM 4.3 The Media Hygiene: Remove or Delete Unused Images and More! plugin for WordPress is vulnerable to unauthorized loss of d… wordfence
44ad056b-8995-4068-8b05-4fefb8d2ff0a
< 2.0.5
MEDIUM 4.3 The Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme theme for WordPress is vulnerable to unauthori… wordfence
44a2e2f3-1902-43c5-8e3c-4174cb1ffa63 MEDIUM 4.3 The WP Page Numbers plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0… wordfence
4490afba-1487-40a4-99c6-c753acb10df3
< 2.13.4
MEDIUM 4.3 The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data… wordfence
448a9e55-e976-4988-a0df-57f1f06fe66d MEDIUM 4.3 The Project Cost Calculator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
44895f32-d5be-4dc7-85d2-539ff1720b37
< 1.0.25
MEDIUM 4.3 The Feeds for TikTok – Display Video Feeds in Grid Layouts plugin for WordPress is vulnerable to unauthorized access d… wordfence
4484fa86-5878-426d-92b9-8eb0751075e5
< 6.10.13
MEDIUM 4.3 The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
447cef6f-fa2e-4087-946d-6e0214830ea9
< 4.0.3
MEDIUM 4.3 The Post Lockdown plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.0.2… wordfence
44777529-660f-4038-bbee-566ca3a8d24e
< 3.2.7
MEDIUM 4.3 The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
4473de39-a122-4c2e-9f64-50157b589a28
< 2.8.8
MEDIUM 4.3 The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
445cee5c-21d5-4597-9efc-84e094476c3e
< 2.0.2
MEDIUM 4.3 The WordPress Booking plugin for Appointment Calendar and Woocommcerce Booking – Bookingor plugin for WordPress is vul… wordfence
4454f002-0d31-4023-9a44-bb8f3050e233
< 1.4.1
MEDIUM 4.3 The Disable Admin Notices individually plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
444a25d7-6837-49a2-b21c-d6a00c0bc0bc MEDIUM 4.3 The Busiprof theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. Th… wordfence
443c59b9-275d-4d17-a870-9ae013c1a5c1
< 1.5.3
MEDIUM 4.3 The Qode Essential Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
442a8f8e-319e-4ae5-8c7f-2bcdcf542158
< 4.7.16
MEDIUM 4.3 The MasterStudy LMS Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 4.7.1… wordfence
4425f63e-2910-4d1c-9f99-0c24fb3350d2
< 1.0.8
MEDIUM 4.3 The FoodBoxBooker plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and includin… wordfence
43fd1949-2682-469b-a129-223ebecc312e
< 7.6
MEDIUM 4.3 The Mark New Posts plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
43fc71bb-87ba-4cf9-ae4d-1cba7bd84806
< 1.2.3
MEDIUM 4.3 The WC Sales Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
43e7b61e-f97a-4889-aae4-3d35ee0c5241
< 1.6.0
MEDIUM 4.3 The Photo Block – A Modern Image Block With Lightbox and Caption Support plugin for WordPress is vulnerable to unautho… wordfence
43d8576b-e6ad-4e0a-b99f-948ba36f53ff MEDIUM 4.3 The WP Landing Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
43d534f8-fb1c-4170-a66e-2cef72cd40de
< 3.0.2
MEDIUM 4.3 The qTranslate X Cleanup and WPML Import plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
43d46ada-4cbf-40e4-a0e5-685d8bf1a8a5
< 2.9.2
MEDIUM 4.3 WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request… wordfence
← Prev 1516 1517 1518 1519 1520 1521 1522 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top