🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1557 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1fd84e08-abc2-4655-999c-6dcdaa7f372c MEDIUM 4.3 The Casengo Live Chat Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
1fcbe3d1-449c-4135-bbf5-9ea9236e5328
< 2.8.7
MEDIUM 4.3 The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request… wordfence
1fc58078-7520-4ee7-b5a1-d6a362ac1860
< 2.1.5
MEDIUM 4.3 The DeepL Pro API translation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
1fc0f287-8f39-4580-b58e-c308a603ba32
< 1.2.6
MEDIUM 4.3 The WP Gravity Forms HubSpot plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1… wordfence
1fa45fa7-b1da-42f0-945b-2a6b0db5ba91 MEDIUM 4.3 The Enable/Disable Auto Login when Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
1f9d4d86-9d5f-4888-9cc4-d55c117ae4ea
< 2.4.0
MEDIUM 4.3 The Different Menu in Different Pages – Control Menu Visibility (All in One) plugin for WordPress is vulnerable to una… wordfence
1f96a0f3-8ebf-40b7-8498-157373e95b22
< 7.1.0.38
MEDIUM 4.3 The Xagio SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
1f7aa23c-ffa7-481b-8481-a36c7ed599d8
< 5.2.6
MEDIUM 4.3 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site R… wordfence
1f66cdcf-cbe5-43e0-ad18-c2b9c4491ed4
< 2.4.2
MEDIUM 4.3 The Music Player for Elementor – Audio Player & Podcast Player plugin for WordPress is vulnerable to unauthorized modi… wordfence
1f533cf9-bec8-48a8-87e3-99117a9948f1 MEDIUM 4.3 The افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری plugin for … wordfence
1f467dde-5b62-407e-bedb-9836630eaabe MEDIUM 4.3 The LinkedInclude plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0… wordfence
1f404b2f-536d-4549-b74b-90b8bbd0edae
< 3.6.21
MEDIUM 4.3 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to a race c… wordfence
1f38676b-270f-4b0f-bc98-a14a26b86a50
< 7.3.13
MEDIUM 4.3 The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… wordfence
1f2b4030-92b1-4795-b72e-761632dd523d
< 1.2.27
MEDIUM 4.3 The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cros… wordfence
1f1dcec6-1fcf-40e8-a15b-647b7161b6b5
< 3.1.10
MEDIUM 4.3 The Eupago Gateway For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
1ef51ffb-df1e-442d-abc8-3a0308099a0b
< 3.42.0
MEDIUM 4.3 The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized… wordfence
1eedab61-e94b-4793-8bf6-cfadd94a5778
< 2.0
MEDIUM 4.3 The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to Cro… wordfence
1ee7fe5f-0939-4604-99fb-2ddd06f30c88 MEDIUM 4.3 The LetterPress – Elevate Your WordPress Site's E-Mail Campaigns and Marketing plugin for WordPress is vulnerable… wordfence
1ee47f62-93f5-40ed-8c1d-555a21eb714a
< 3.7.0
MEDIUM 4.3 The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and meta… wordfence
1ee41498-f5c6-48c3-a0db-55a1fe6e7f92 MEDIUM 4.3 The infolinks Ad Wrap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
1ebe0767-db22-4995-bdf1-5ebb48f960e9 MEDIUM 4.3 The Quote Comments plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0… wordfence
1ebb5d2c-2357-49a0-ac39-045cc1d4c0b3
< 1.1.2
MEDIUM 4.3 The ads.txt Guru Connect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
1eb25ef3-28ea-4f8f-932a-e90ca1914e8d
< 6.9.19
MEDIUM 4.3 The Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More plugin for WordPress is vu… wordfence
1e9fa1f8-5070-4e2f-a5ee-810eccf7ec4d
< 7.0.6
MEDIUM 4.3 The Ecwid Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
1e9b094a-29ba-4be3-9033-fd915fae1820
< 3.8.1
MEDIUM 4.3 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure … wordfence
← Prev 1554 1555 1556 1557 1558 1559 1560 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top