🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1559 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1da09e8c-e9d8-4bbf-afdd-4bf49dc3b598 MEDIUM 4.3 The Cackle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.33. … wordfence
1d8fa778-420f-4cc4-a609-17c426789a35 MEDIUM 4.3 The Houzez theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4… wordfence
1d8c53cd-c35e-44db-8e61-da8f02ee6025 MEDIUM 4.3 The Kwayy HTML Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
1d7ffc0b-2706-4707-9b8f-edcb418058ca MEDIUM 4.3 The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
1d6e97cd-7da7-43ab-bd88-ebd442d50aa3 MEDIUM 4.3 The Broken Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2… wordfence
1d5d4264-a293-43fc-98a9-b490a37b0c6b MEDIUM 4.3 The Light Poll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
1d4dfcb3-8749-4b63-b68e-cc2742f82381 MEDIUM 4.3 The Century ToolKit plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
1d4b1446-f525-406a-9374-31c8a754d378
< 7.8.0
MEDIUM 4.3 The SUMO Memberships for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
1d4276c2-7c53-425b-9b97-b6812fc32047
< 7.41
MEDIUM 4.3 The Custom Admin Interface plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
1d3eddce-1b41-4a33-8d57-bd594cf06a06
< 4.18
MEDIUM 4.3 The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. T… wordfence
1d3e476d-0885-4e8c-a682-bd64d9f13b53
< 1.7.1
MEDIUM 4.3 The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin plugin for WordPress is vulnerable to unautho… wordfence
1d3cc32b-e415-4350-811a-c799a6ec24b6
< 3.9.14
MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Expos… wordfence
1d387d8e-198c-476a-9688-6842a871571e
< 1.2.9
MEDIUM 4.3 The Hash Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.8. … wordfence
1d12f5c5-2f81-4cf5-9ba9-e0949fc5bb48 MEDIUM 4.3 The Społecznościowa 6 PL 2013 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
1d0a40f8-4c31-447d-ac28-73cfe7a07687
< 4.7
MEDIUM 4.3 The EventON PRO - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
1cee249d-0a0e-4675-9e35-3a177a3b74a2 MEDIUM 4.3 The Custom Skins Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… wordfence
1cec03d3-0e80-4025-b782-1ce9c3237569
< 3.7.1
MEDIUM 4.3 The Contact Us Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… wordfence
1cebb69a-3096-48fa-903c-b4eff62eec6d MEDIUM 4.3 The Bard theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in ver… wordfence
1ce7c895-e94c-46bd-9de1-f5fde29c3475
< 2.0.3
MEDIUM 4.3 The Cool Timeline (Horizontal & Vertical Timeline) plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
1cdadc61-8a8d-446a-8f7e-9fecd7d687b1
< 1.0.21
MEDIUM 4.3 The Poptics – Popup Builder, Email Opt-ins, Exit-Intent & WooCommerce Popups Sales plugin for WordPress is vulnerable … wordfence
1cd5acfc-0338-4958-8f46-3d7b14ef0e14
< 1.4.1
MEDIUM 4.3 The Media Library Downloader plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
1ccc8b30-1bdf-4335-85a9-79c6f9a88afc
< 1.0.7
MEDIUM 4.3 The Sweet Energy Efficiency plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data du… wordfence
1cc64898-8724-4ba5-9260-02c647812cc8 MEDIUM 4.3 The BD Courier Order Ratio Checker plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
1cb265d8-eb18-42ee-9141-2fe81c0c4585 MEDIUM 4.3 The WP Google Tag Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
1cb1d8a3-91dd-419e-bc4e-57842afeb7b1
< 1.3.70
MEDIUM 4.3 The Appointment Booking Calendar plugin for WordPress is vulnerable to authorization bypass due to a missing capability … wordfence
← Prev 1556 1557 1558 1559 1560 1561 1562 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top