πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1582 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
04b341ae-f856-4bdb-b9d0-696c25131bd0
< 9.5.4.1
MEDIUM 4.3 The Really Simple Security Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up… wordfence
04b2123d-ae0c-4984-95f5-7040f8604c92
< 26.6
MEDIUM 4.3 The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and includi… wordfence
04ad816b-0ac0-44b5-928a-5bb3e36523b2
< 3.0.7
MEDIUM 4.3 The Advance Menu Manager plugin for WordPress is vulnerable to unauthorized modification of data due to missing capabili… wordfence
04a119c2-7fce-4836-8214-ca088f6c92ee MEDIUM 4.3 The Appender plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
048768bf-326c-455e-919c-9691d6537062
< 4.1.6
MEDIUM 4.3 The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
048277c4-f313-484d-a330-420e0682eee2
< 1.12.7
MEDIUM 4.3 The WP ERP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … wordfence
047fd07c-ab07-49bf-8a94-8ae33c92f93e
< 1.4.0
MEDIUM 4.3 The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
047c04f7-f787-41b6-9d9a-0b58e26fea37
< 2.2.2
MEDIUM 4.3 The EKC Tournament Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
0472804e-00cc-4c4c-97aa-86f433f65782
< 4.24
MEDIUM 4.3 The Maps Widget for Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
0457cd72-d9ce-4b88-88ee-b1270359485f
< 1.3.53
MEDIUM 4.3 The Materialis Companion plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
044c34da-ee4e-4c18-bf9e-96a49a5ea7d9
< 2.4.7
MEDIUM 4.3 The Restaurant Menu and Food Ordering by Five Star Plugins plugin for WordPress is vulnerable to Cross-Site Request Forg… wordfence
04401d7e-996d-4b46-b391-bfb0b065900b
< 1.0.42
MEDIUM 4.3 The Flo Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
04390ec2-c4d4-4396-b64f-e5c878d87bc8 MEDIUM 4.3 The Payment Gateway Authorize.Net CIM for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a… wordfence
041830b8-f059-46f5-961b-3ba908d161f9
< 5.4.9
MEDIUM 4.3 The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8… wordfence
0407c2fa-5bca-4ef2-bba7-e5975ea94f60
< 6.0
MEDIUM 4.3 The WP Delete Post Copies plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
04045549-6a8f-427e-bb73-26b2c75c8623 MEDIUM 4.3 The GP Back To Top plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
03fd2eee-429c-4053-8105-e1816f99ea91
< 1.9.12
MEDIUM 4.3 The Spacious theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
03f9d9bb-6a87-4da9-bbb0-65203d7250e9
< 2.4.17
MEDIUM 4.3 The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missi… wordfence
03d89a2d-51e5-420c-9a57-2999a30a9d16
< 1.0.5
MEDIUM 4.3 The WP Email Log – PostBox plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabili… wordfence
03d50486-2546-4d59-9e20-2e692046a176 MEDIUM 4.3 The WordPress Mobile Themes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
03d3f47d-4e17-46a9-a937-9222d3ebcde5
< 1.5.5
MEDIUM 4.3 The Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including,… wordfence
03b8b5a2-979d-42d0-86f5-48ee73162d22
< 2.0.7
MEDIUM 4.3 The Transients Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
03b88862-012a-4dc6-9abb-99dc0d9408fd
< 5.0.14
MEDIUM 4.3 The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
03abb277-d658-440a-a7f7-34d80d8d1cd6 MEDIUM 4.3 The Headinger for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
039d2a35-fbd9-467b-ae98-2d47ff03fb2e
< 1.14
MEDIUM 4.3 The AJAX Thumbnail Rebuild plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
← Prev 1579 1580 1581 1582 1583 1584 1585 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top