🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1548 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
249ad768-3706-47c6-ad1d-f11900b87608
< 2.4.8
MEDIUM 4.3 The HT Mega plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on… wordfence
24971249-ea45-4477-a219-075fd8a1399c MEDIUM 4.3 The Advanced Custom Fields : CPT Options Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… wordfence
248b74d3-5228-473d-a79a-743566898606
< 3.1.43
MEDIUM 4.3 The Simple Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… wordfence
248750b0-0fed-4c31-aeeb-709da3e7e2a1
< 1.9.17
MEDIUM 4.3 The Academy LMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on afunction… wordfence
24781100-68cc-4d1a-9c02-cf1378fae7c5
< 1.1.0
MEDIUM 4.3 The Accessibility by AudioEye plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
24747507-8f24-499e-a257-d379dc171e18
< 2.7.10
MEDIUM 4.3 The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
246a66ea-7f2f-44e6-825b-5556eacc33ab
< 2.2.2
MEDIUM 4.3 The Boom Fest plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
245e2a05-34e7-402c-b230-5c41ee88264b
< 1.2.8
MEDIUM 4.3 The WP AI CoPilot – AI content writer plugin, ChatGPT WordPress, GPT-3/4 , Ai assistance plugin for WordPress is vulne… wordfence
24578138-a0f3-4175-abea-eff0fbcba169
< 1.1.6
MEDIUM 4.3 The Admin login URL Change plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
244eba91-343a-4e91-96b8-207686d02ce6
< 3.3.33
MEDIUM 4.3 The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… wordfence
244d4c73-3b50-4426-9730-f854372d2ba5
< 3.8.4
MEDIUM 4.3 The ShortPixel Adaptive Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
24351ff6-874d-427b-8fd6-3ebc5c53ec4a
< 3.4.7
MEDIUM 4.3 The Official CleverReach® Plugin for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
24347126-56f5-4fb2-afcd-52af0b879eb0
< 2.5.4
MEDIUM 4.3 The Ocean Extra plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
243200f4-5a5d-4275-bf2b-f4cb6099d145 MEDIUM 4.3 The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all… wordfence
242a3c60-b8ca-43cc-92d7-eb3830381512
< 1.6.162
MEDIUM 4.3 The Mesmerize Companion plugin for WordPress is vulnerable to unauthorized access and modification of data due to a miss… wordfence
24285f69-6474-4a2d-9c20-af27f1ca98c9
< 4.0.3
MEDIUM 4.3 The Bubble Menu – circle floating menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
24142874-95f9-448d-8cf2-14a65fc946ab
< 1.2.6
MEDIUM 4.3 The Paid Memberships Pro - Member Directory Add On plugin for WordPress is vulnerable to Sensitive Information Exposure … wordfence
240f1845-5566-43d7-9125-78c244e2913a
< 3.0.4
MEDIUM 4.3 The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
240f05b0-876d-449c-ade0-118b1e3ab206
< 1.2.5
MEDIUM 4.3 The Sticky Notes for WP Dashboard plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
24009534-3a57-4ed3-b841-72e87e2a6925
< 3.9.6
MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access due to … wordfence
23f9d758-4b5e-44e5-9f58-a37b01c4ffdb MEDIUM 4.3 The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
23f00e28-4ad1-4ae6-8d43-12097ee6bf90 MEDIUM 4.3 The Youtube Video Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
23e3c738-268e-4467-ad73-fe9b355b3000 MEDIUM 4.3 The DesignO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0… wordfence
23d7b6fc-0eb7-4bd1-ac48-3797aec08496
< 1.0.3
MEDIUM 4.3 The Privyr CRM – Instant Lead Alerts for Contact Forms plugin for WordPress is vulnerable to unauthorized access due t… wordfence
23b46e5b-ce1e-4215-921c-edea7fd6c56a
< 1.2.0
MEDIUM 4.3 The Delete Usermeta plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
← Prev 1545 1546 1547 1548 1549 1550 1551 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top