πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 466 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4fcaab95-7940-45f9-a3c2-c3b0dc540b61
< 1.2.5
MEDIUM 6.5 The Database for CF7 plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check o… wordfence
4f96b87a-1405-4cf6-b903-ad0c7c8e2826
< 4.27.2
MEDIUM 6.5 The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches f… wordfence
4f6d0e20-9a30-4628-a090-feb1f0adc8af MEDIUM 6.5 The New Simple Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.0 due to … wordfence
4f5ff7bc-9443-4b34-abd3-dac800f162a1
< 4.5.1
MEDIUM 6.5 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection vi… wordfence
4f57cac9-5610-454b-affb-86384ea00881
< 7.0.11
MEDIUM 6.5 The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. … wordfence
4f2fd4a2-4a99-479e-aa9d-3d847ba8f00c MEDIUM 6.5 The Menus Plus+ plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9.6 due to insuf… wordfence
4f1ed4a2-eb0d-42cd-9273-10d7d127cdf9 MEDIUM 6.5 The lasTunes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.… wordfence
4f17976e-d6b9-40fb-b2fb-d60bcfd68d12
< 0.9.69
MEDIUM 6.5 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
4f145c85-f3c6-46a7-b8ae-d486dd23087d
< 3.0.1
MEDIUM 6.5 The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data … wordfence
4ed81348-7604-4858-bc8e-b4504d77ee45
< 3.1.2
MEDIUM 6.5 The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to Insecure Direct … wordfence
4e5d7d04-f73a-48ea-81e3-36a514c76cc6
< 1.3
MEDIUM 6.5 The RapidResult plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and inc… wordfence
4e4f0275-7689-4b72-9761-45534f9c706d MEDIUM 6.5 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to unauthorized access du… wordfence
4e4df9a6-8f7d-428b-a596-0751ca047169
< 4.7.1
MEDIUM 6.5 The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, a… wordfence
4e41a12d-44a6-4851-b72a-ffa65bbbeb0b
< 1.2.8
MEDIUM 6.5 The WIP Custom Login plugin for WordPress is vulnerable to authorization bypass due to a missing capability and nonce ch… wordfence
4e3a6fe2-6292-44ff-8925-a4aeb77c2a7f
< 5.9.7
MEDIUM 6.5 WordPress Core processes shortcodes in user-generated content on block themes in versions up to, and including, 6.2.1. T… wordfence
4e0f38db-84bb-4ba9-9068-40937e78010d
< 10.0.1
MEDIUM 6.5 The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injec… wordfence
4dfc28ec-1411-43c3-833e-a6c85a3ed767
< 3.1.3
MEDIUM 6.5 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor… wordfence
4df46cb5-11a9-4c44-8329-4fc8086bc367 MEDIUM 6.5 The WooCommerce Orders & Customers Exporter plugin for WordPress is vulnerable to SQL Injection in versions up to, and i… wordfence
4dd63ea6-7821-42b8-9b52-e721a8b2382d MEDIUM 6.5 The Quicksand Post Filter jQuery Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up … wordfence
4db55163-3037-4a3a-97a0-2a3109a8245d
< 1.0.42
MEDIUM 6.5 The Wishlist plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.41 due to insuffi… wordfence
4d9ef3ab-fdba-4f9c-9323-0731a8d9db54
< 2.1.30
MEDIUM 6.5 The The Cozy Blocks – All-in-One Page Builder Blocks for Gutenberg and Full Site Editing (FSE) plugin for WordPress is… wordfence
4d59eedb-550f-44c1-a0cd-609c5661134d
< 2.11.22
MEDIUM 6.5 The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the cookie in all versions up to, and inc… wordfence
4cf89f94-587a-4fed-a6e4-3876b7dbc9ba
< 5.0.20
MEDIUM 6.5 The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, an… wordfence
4c956651-4f5e-4e2d-a0f2-b02d4f25bd68
< 1.2.5
MEDIUM 6.5 The Accordion and Accordion Slider plugin for WordPress is vulnerable to unauthorized access of data and modification of… wordfence
4c1d49d0-c9aa-401c-80b9-d4df7fe97691
< 1.4.1.9
MEDIUM 6.5 The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode E… wordfence
← Prev 463 464 465 466 467 468 469 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top