πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1521 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
426f0993-8b75-4bb1-9368-8927241d7cda
< 2.2.14
MEDIUM 4.3 The Breeze – WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
4243bd6d-34f6-4d29-a333-4499a2e2d2e1
< 2.2.5.2
MEDIUM 4.3 The SecuPress Free β€” WordPress Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
4238ce95-ff9a-492f-b3ef-3b263efdda7b
< 3.8.5
MEDIUM 4.3 The WP-Lister Lite for eBay plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
42303b60-cbb5-4176-94f9-b2ed29f59cc8 MEDIUM 4.3 The Bulk Comment Remove plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
421fcee2-a05d-4486-837e-ddee3d73d737
< 2.4.8
MEDIUM 4.3 The EventON Lite plugin for WordPress is vulnerable to Information Exposure in all versions less than, or equal to, 2.4.… wordfence
421ed38f-cf0b-437f-a477-5bae7963e9e6
< 1.6.44
MEDIUM 4.3 The One Page Express Companion plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
420f56de-4c83-4c9f-933c-0422467bbc7a
< 4.0.9
MEDIUM 4.3 The User Activity Tracking and Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
41fada19-c697-4078-825b-0bdf6a827b02
< 1.6.0
MEDIUM 4.3 The PHP Compatibility Checker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
41ecc6fc-5178-40db-84da-665d60816345 MEDIUM 4.3 The Social Profilr plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
41d9786e-4ce3-42d6-a0d6-8eb863103d5c
< 5.5
MEDIUM 4.3 The Animated Rotating Words plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
41ce3250-17aa-41d6-835d-b37a498c9a29 MEDIUM 4.3 The Image slider with description plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
41b0b12f-ff52-4913-aa54-3fbaf0839959
< 1.4.4
MEDIUM 4.3 The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize… wordfence
41aeb465-48c2-48db-90ea-186ceeac6753
< 1.2.5
MEDIUM 4.3 The Serious Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
41ac45c7-6741-4b7c-ab74-fd2dfd3c31d1
< 3.2.21
MEDIUM 4.3 The VPSUForm – No-Code Custom Form Builder – Contact Forms, Conversion Form & More plugin for WordPress is vulnerabl… wordfence
41a38bb5-a474-4a78-b28d-0d730097b4cb MEDIUM 4.3 The Woo File Dropzone plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida… wordfence
41960c28-80f9-4c50-8b4b-b1175695a6f4
< 1.1.2
MEDIUM 4.3 The Advanced All in One Admin Search by WP Spotlight plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
418b9138-9ae0-41f1-a75b-69cbcaffbb88
< 7.33
MEDIUM 4.3 The WP Custom Admin Interface plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… wordfence
4181dcad-b5bd-46db-b47c-3cdee427123c
< 3.11.13
MEDIUM 4.3 The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includi… wordfence
417ae2f2-e245-49bb-8b77-0eabf6095459
< 3.0.9
MEDIUM 4.3 The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
416da5d4-3d47-443b-a82c-c059c38f5218
< 1.5.7.1
MEDIUM 4.3 The Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7.… wordfence
4169ad47-7b66-433e-8184-cef0d0fec476
< 4.1.20
MEDIUM 4.3 The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Sensi… wordfence
415d69d9-2afd-41f8-8339-ea32fac3aa48
< 9.3.9
MEDIUM 4.3 The XStore theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
4154aa02-7fa1-4858-bea7-092ec4a508ac
< 2.1.4
MEDIUM 4.3 The Social Media Feather plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
4147e973-5a17-41d8-b8d9-5e43a23c9bc9
< 11.0
MEDIUM 4.3 The Sort SearchResult By Title plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
414165a3-78f8-4254-ac24-2de177cad3dd
< 1.11.0
MEDIUM 4.3 The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
← Prev 1518 1519 1520 1521 1522 1523 1524 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top