πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1520 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
43d24ac2-c3b9-4e5e-9b58-c99bacc56495
< 2.2.5
MEDIUM 4.3 The Premmerce Product Search for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
43d01824-507d-4d26-af88-9ea5b4c1b108
< 9.0.41
MEDIUM 4.3 The WP Go Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.0.40… wordfence
43c4ca71-0bf0-4529-97d9-2349f96bbb9e
< 2.6.4
MEDIUM 4.3 The Mollie Forms plugin for WordPress is vulnerable to unauthorized post or page duplication due to a missing capability… wordfence
43b05697-bc36-4f32-86b4-2feef892fe42
< 2.9.7.2
MEDIUM 4.3 The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vul… wordfence
43af2d38-72e8-405f-a910-500fb782ded2 MEDIUM 4.3 The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
43a237fd-5d3a-47fb-bacf-ceb5eeaa8bbb MEDIUM 4.3 The Quantic Social Image Hover plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
439e7c0d-e45a-44f2-9ecb-3092843f63e0
< 2.4.0
MEDIUM 4.3 The Visual Link Preview plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … wordfence
439809ad-21ea-4a0b-b1fd-5de9f8f5ee7a
< 4.2.1
MEDIUM 4.3 The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direc… wordfence
4394f96a-ceb5-463f-b454-a6fa4a59fc45
< 3.7.40
MEDIUM 4.3 WordPress Core is vulnerable to information disclosure via the REST-API in versions up to 6.0.3. The REST API endpoint f… wordfence
4381d22f-5607-4b54-9762-33ac6611a658
< 4.4
MEDIUM 4.3 The WP Maintenance Mode & Site Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
43790bc7-23ff-48b1-bf49-bf13cf184bd1 MEDIUM 4.3 The Backup Bolt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
434b140a-43b7-41bc-8cc2-ed82787b90c3
< 6.1.10
MEDIUM 4.3 The Essential Addons for Elementor – Popular Elementor Addon With Ready Templates, Advanced Widgets, Kits & WooCommerc… wordfence
4340ef32-82d4-4523-ae63-36f0ef853f76
< 3.5.7
MEDIUM 4.3 The YayPricing plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 3.5.6. This i… wordfence
433a03c2-09fd-4ce6-843b-55ad09f4b4f7
< 2.9.35
MEDIUM 4.3 The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
432b11be-174d-45d6-aa3b-2fbfa85ec17a
< 4.3.12
MEDIUM 4.3 The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This … wordfence
42fff63c-62ec-466e-9a05-60d76f80039e
< 1.0.9
MEDIUM 4.3 The Easy Hide Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
42f8f378-0f84-49ad-b95e-6abb3a94df7e
< 4.5.3
MEDIUM 4.3 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 4.5.3. … wordfence
42e63318-661e-465d-919f-df0635ea1a6d
< 1.4.4
MEDIUM 4.3 The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. T… wordfence
42b77d66-8519-4e7e-b253-fefac581df4b
< 10.2.3
MEDIUM 4.3 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Cross-Site Request… wordfence
42b2d840-4e8b-4027-ab3b-78b17c9ed9aa
< 1.2.2
MEDIUM 4.3 The Floating Action Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
42ac91dc-bcde-4804-bac7-b96597627a27
< 4.0.4
MEDIUM 4.3 The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie C… wordfence
42a14820-710d-4149-9a8d-aa84479f0980
< 6.4.9
MEDIUM 4.3 The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
4280f2db-cabe-4955-af68-d03e299bfcf4
< 0.99
MEDIUM 4.3 The Simple Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0… wordfence
4276e68b-4d0d-4a16-a32c-51b4f6e3c570 MEDIUM 4.3 The CBX Restaurant Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
42711f2d-99e4-45cf-bd57-a3e228f3bf25 MEDIUM 4.3 The Easy Child Theme Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
← Prev 1517 1518 1519 1520 1521 1522 1523 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top