πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1554 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1e48639e-01bb-4980-be6f-bcea3dd16fc5
< 2.0.5
MEDIUM 4.3 The Download Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
1e3ba5cf-1c70-4b6e-ab76-0103dad44732
< 3.0.0
MEDIUM 4.3 The GA4WP: Google Analytics for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
1e2c937c-1ff8-4bcc-913b-83bade37d754
< 2.1.9
MEDIUM 4.3 The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu… wordfence
1e280530-74de-42d2-bffe-3db24f72636d
< 6.2.2
MEDIUM 4.3 The Herd Effects plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2.… wordfence
1e1db52a-3966-4e04-b0ed-08bda9ba1ff6
< 1.27
MEDIUM 4.3 The Republish Old Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
1e19ef28-5223-4ced-b9f2-3c5aa5d91264 MEDIUM 4.3 The Conditional Cart Messages for WooCommerce – YourPlugins.com plugin for WordPress is vulnerable to Cross-Site R… wordfence
1e07e570-e4c0-472c-b582-40a87a6507bf
< 6.6.3
MEDIUM 4.3 The WP SMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.2. Thi… wordfence
1dff665d-df42-4b67-bea2-4d6273714d8d
< 3.0.17
MEDIUM 4.3 The Animator – Scroll Triggered Animations plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
1df31843-0af7-486c-b0aa-4eaf72a7e70f
< 2.25.26
MEDIUM 4.3 The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
1de8da4c-dee7-4d59-a475-a969008aa0d4
< 1.9.9
MEDIUM 4.3 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure… wordfence
1ddfd5d9-a7e4-42a8-8419-9a35b4781d3c
< 3.8.6
MEDIUM 4.3 The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to authorization bypass due to incorrectly defined… wordfence
1ddcd2eb-fd7a-48b7-b9ea-3632d49e9734
< 2.9.35
MEDIUM 4.3 The MasterStudy LMS WordPress Plugin is vulnerable to unauthorized access of data due to a missing capability check on … wordfence
1dd4e39a-9b2f-4728-b026-2dee60257c46
< 3.2
MEDIUM 4.3 The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
1db1c415-7c57-47bb-82d9-44168259ae1a
< 2.4.1
MEDIUM 4.3 The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
1da1d851-10ba-45e8-a486-03ac409075a4 MEDIUM 4.3 The WPBookit plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… wordfence
1da09e8c-e9d8-4bbf-afdd-4bf49dc3b598 MEDIUM 4.3 The Cackle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.33. … wordfence
1d8fa778-420f-4cc4-a609-17c426789a35 MEDIUM 4.3 The Houzez theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4… wordfence
1d8c53cd-c35e-44db-8e61-da8f02ee6025 MEDIUM 4.3 The Kwayy HTML Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
1d7ffc0b-2706-4707-9b8f-edcb418058ca MEDIUM 4.3 The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
1d6e97cd-7da7-43ab-bd88-ebd442d50aa3 MEDIUM 4.3 The Broken Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2… wordfence
1d5d4264-a293-43fc-98a9-b490a37b0c6b MEDIUM 4.3 The Light Poll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
1d4dfcb3-8749-4b63-b68e-cc2742f82381 MEDIUM 4.3 The Century ToolKit plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
1d4b1446-f525-406a-9374-31c8a754d378
< 7.8.0
MEDIUM 4.3 The SUMO Memberships for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
1d4276c2-7c53-425b-9b97-b6812fc32047
< 7.41
MEDIUM 4.3 The Custom Admin Interface plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
1d3eddce-1b41-4a33-8d57-bd594cf06a06
< 4.18
MEDIUM 4.3 The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. T… wordfence
← Prev 1551 1552 1553 1554 1555 1556 1557 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top