πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1562 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1a7bdae1-b28a-4fc6-9538-944ffeb32796
< 4.25.2
MEDIUM 4.3 The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. Th… wordfence
1a79d08e-9429-4895-bc0c-cfaa8eb161d6 MEDIUM 4.3 The WP Posts Re-order plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
1a6bc58f-9cf3-4d3f-a10e-0ccde0b890a3
< 1.2.2
MEDIUM 4.3 The Injection Guard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
1a6ba67d-d10d-4590-8398-26b29c044fb3
< 1.17.6
MEDIUM 4.3 The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to unauthorized ac… wordfence
1a618dbf-1180-4937-8466-5abc784a3365 MEDIUM 4.3 The HidePost plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.… wordfence
1a5ef5b3-2900-44f0-9e13-66fbdc937b38 MEDIUM 4.3 The Alex User Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
1a4dfbbe-19b9-4e8a-bf2f-c6a3d4759848 MEDIUM 4.3 The Templazee plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
1a4bc52d-5771-4e7b-a394-772f2a5edbd7
< 5.8
MEDIUM 4.3 The WP Scraper plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_scr… wordfence
1a47b096-43c8-4fc4-9fe1-0afa311a420c
< 1.5.10
MEDIUM 4.3 The VOD Infomaniak plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
1a46fd57-4cb9-4d98-89b6-926d74b2ab33 MEDIUM 4.3 The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the init_end… wordfence
1a358381-fe1e-4ebd-ba28-069ee8580ec3
< 3.6.17
MEDIUM 4.3 The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
1a304e9a-9518-4a6a-b36a-963cb329f5c3
< 2.7.3
MEDIUM 4.3 The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized access of data d… wordfence
1a148e36-951d-4cfd-96df-f059bd4756bc MEDIUM 4.3 The WAH Forms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
1a033ffd-bcff-4803-812b-abfc6d5135e5
< 1.9.2
MEDIUM 4.3 The Subscription & Recurring Payment for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
1a0136e2-97f5-4368-a805-0f60d1b8ad11
< 1.1.7
MEDIUM 4.3 The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions … wordfence
19f126f8-1d59-44b5-8e0e-c37f1fbedf5a
< 1.7.2
MEDIUM 4.3 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missi… wordfence
19ed8044-e7fb-482f-9a20-931ccd2a4e47 MEDIUM 4.3 The Erima Zarinpal Donate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
19ec4be7-200d-418b-8af2-8460edbc817a
< 3.1.3
MEDIUM 4.3 The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
19e89442-e9cd-4493-a338-b887b436c37c
< 5.0
MEDIUM 4.3 The Simple User Avatar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and… wordfence
19e73c54-9951-474d-bcc8-1fa6349d46c0 MEDIUM 4.3 The Interactive Page Hierarchy plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
19e0757c-593b-42ef-87b2-2eca23416b2d
< 2.1.3.6
MEDIUM 4.3 The 3DPrint Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
19dd6670-2813-4944-abcd-c26fb9b82092
< 6.21
MEDIUM 4.3 The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
19da439e-2ff2-4119-b688-27bc7f206a5d
< 1.9.2
MEDIUM 4.3 The Simple Membership WP user Import plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
19d50a14-dbef-476d-8171-24ef84f380f3
< 1.0.14
MEDIUM 4.3 The Premmerce User Roles plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
19d08a16-51c1-4255-b0e0-01307e1783ca MEDIUM 4.3 The LH Password Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
← Prev 1559 1560 1561 1562 1563 1564 1565 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top