🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1075 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
89df3005-0967-474f-8a4e-3b23273dd1a2
< 3.4.5
MEDIUM 5.4 The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Obj… wordfence
89d1fa00-4757-4f86-bddb-a6a2dbcf9625
< 3.5.4.4
MEDIUM 5.4 The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Chec… wordfence
89bc17fd-14e8-4210-8cf7-a043d1ea9c22 MEDIUM 5.4 The Simple PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the googlepdf shortcode in v… wordfence
89a23d5a-7728-403e-b654-595d92c20b66
< 1.3.8
MEDIUM 5.4 The eRoom – Zoom Meetings & Webinar plugin for WordPress is vulnerable to unauthorized setting update due to missing … wordfence
8910d60c-45be-41a1-86fb-a0d60a78e660
< 2.2.5
MEDIUM 5.4 The WordPress Landing Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘open-tab' pa… wordfence
88b0acee-f378-487d-8ab9-96146e0cde10
< 1.6.3
MEDIUM 5.4 The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable… wordfence
88898997-6199-4b33-bd35-70a1a01812ec
< 3.2.1
MEDIUM 5.4 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to unauthorized access to a… wordfence
884c4508-1ee1-4384-9fc2-29e2c9042426
< 4.3.2.2
MEDIUM 5.4 The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and… wordfence
88097744-d2f5-4ae5-aa71-0f4a0decd911
< 2.1.0
MEDIUM 5.4 The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
88068243-9e2a-4893-a432-fd1973db7ca8
< 1.1.6
MEDIUM 5.4 The Pop-up plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.1.5. This make… wordfence
87e32ddb-6f3e-4896-965c-f30b016f9a72
< 2.3.1
MEDIUM 5.4 The ЮKassa для WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability ch… wordfence
87a2f576-2e72-44c9-a379-b24bee273ee5
< 1.4
MEDIUM 5.4 The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.… wordfence
874b4d60-153a-44e5-b7c5-037ba66b34ea
< 2.0.22
MEDIUM 5.4 The Market Exporter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
87333eee-36ae-4272-b300-7352eb133745
< 3.3.2
MEDIUM 5.4 Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before … wordfence
872c42d5-56f4-4825-b664-92e43b6d089a MEDIUM 5.4 The Idealien Category Enhancements plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
86f3c549-2cdd-4294-bc62-0892e94ddbb7
< 1.8.1
MEDIUM 5.4 The Qubely plugin for WordPress contains an incorrect authorization weakness that makes it possible for contributor-leve… wordfence
86ddd5fd-137b-478e-952e-b36fc6a5c28d
< 2.8.5
MEDIUM 5.4 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
86c04e9d-0bcd-4637-bd4a-aeb2e3f373ff
< 5.1.7
MEDIUM 5.4 Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.… wordfence
86b9b17f-f819-4316-8565-4e7603cd5de7 MEDIUM 5.4 The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when … wordfence
86b54c46-a637-4fc4-8d48-a02383c9814b
< 4.21.1
MEDIUM 5.4 The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management S… wordfence
8698d6dd-7376-4d29-8a5c-21c239a7aa03
< 3.20.2
MEDIUM 5.4 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Med… wordfence
8619c999-5cf7-4888-bdb2-815238411303
< 1.3.92
MEDIUM 5.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo … wordfence
86167b8c-6d4e-495d-96f7-8cda8e2c80b8
< 1.5.2
MEDIUM 5.4 The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Arbitrary Options Deletion i… wordfence
860848c1-dd67-4baf-a571-bc866c5f12f8
< 4.0.2
MEDIUM 5.4 The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access… wordfence
85ba54cc-3ef8-49ee-bef0-6fef8e116871 MEDIUM 5.4 The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XS… wordfence
← Prev 1072 1073 1074 1075 1076 1077 1078 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top