πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,434
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 1, 2026
Last Updated

40,434 vulnerabilities found (page 1556 of 1618)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1c61b3a7-25a9-4890-a294-378883ebe11d
< 1.10.32
MEDIUM 4.3 The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
1c51a3f8-dee1-4744-8353-864312c89021
< 2.2.1
MEDIUM 4.3 The WP 2FA plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the login_for… wordfence
1c4b3c9a-ed3e-460b-ac35-dd2c91b30cd8
< 5.1.11
MEDIUM 4.3 The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
1c3a29ec-16f0-4fad-b188-7a683d123bb8
< 4.0.3
MEDIUM 4.3 The SureCart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
1c24f881-52bc-4210-9037-bcdd1e4aa895
< 1.4.0
MEDIUM 4.3 The Best Restaurant Menu by PriceListo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
1c22717f-494e-4f62-9691-ee5a3366a487
< 1.1.4
MEDIUM 4.3 The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of settings due to a missing ca… wordfence
1c1e1c18-fecd-45a9-a515-11073c9f1aec
< 3.7.1.1
MEDIUM 4.3 The JetEngine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
1c08c309-af52-4aed-8cc3-b93488f3396f
< 1.7.1
MEDIUM 4.3 The Lemmony theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.7.1. This is due to miss… wordfence
1bfb5d34-738d-4842-be93-9668fceb3334
< 2.8.2
MEDIUM 4.3 The Social Media & Share Icons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … wordfence
1bf798b5-2a5c-42d9-a4b3-d3ed056e1fdb
< 2.7.2.3
MEDIUM 4.3 The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
1bea21d5-da96-48fd-89bb-57aea88af793 MEDIUM 4.3 The Simple XML Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
1be686d3-16b1-4ec7-b304-848ca4d7162c
< 3.3.0
MEDIUM 4.3 The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … wordfence
1bd8b315-97a9-40f4-99cb-76f347a5c1e9
< 12.1.2
MEDIUM 4.3 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to unauthorized access due to a … wordfence
1bd308a4-7157-4bc6-a55b-c6a4a62510a9
< 2.1.3
MEDIUM 4.3 The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in… wordfence
1bb55b22-a0d0-424f-8e4f-57d3f239c149
< 1.7.2
MEDIUM 4.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a mi… wordfence
1baf7c7e-b5e9-40b5-9c96-abe6ebcf2b2a
< 1.7.9
MEDIUM 4.3 The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated… wordfence
1ba7b675-54d6-4f0e-b60f-1c7fa6ff24ea
< 3.2.1
MEDIUM 4.3 The WordPress Mega Menu – QuadMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
1ba56d68-e104-4a79-b5b4-627f9617043b
< 1.3.35
MEDIUM 4.3 The CP Contact Form with Paypal plugin for WordPress is vulnerable to missing authorization on the 'cpcfwpp_feedback' fu… wordfence
1ba33c84-5198-4c77-8995-d0a315d68990
< 1.7.13
MEDIUM 4.3 The 360 Javascript Viewer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
1b9ed184-814d-46cb-979c-908bc9359fae
< 5.0.7
MEDIUM 4.3 The Swift SMTP (formerly Welcome Email Editor) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v… wordfence
1b9103b9-a33d-4838-9454-70fa5277c5a0
< 1.0.36
MEDIUM 4.3 The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
1b8d88e4-a9dc-4740-b836-99f730beefcb
< 3.9.0
MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Expos… wordfence
1b82ce74-11ac-4719-961d-a16717ce023b
< 2.3.4
MEDIUM 4.3 The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin f… wordfence
1b5de554-1d2f-4932-9f93-1333b07edeba
< 1.2.8
MEDIUM 4.3 The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2… wordfence
1b3bd31f-0f5a-4b4a-811b-5482db866bd5 MEDIUM 4.3 The AutoCatSet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.… wordfence
← Prev 1553 1554 1555 1556 1557 1558 1559 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top