πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1103 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fbd74378-ce7b-4438-81d4-fc164005a832
< 4.3.6
MEDIUM 5.3 The Content Protector (Passster) plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to,… wordfence
fbc7e515-c712-4a39-a0f7-c3f646083060
< 2.1.2
MEDIUM 5.3 The Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy plugin for WordPress is vulnerable to unauthorized acc… wordfence
fbb7624c-848f-485b-b4df-866ebf45d3a0
< 5.24.1
MEDIUM 5.3 The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to Sensitive Informati… wordfence
fbac8033-9248-4921-86c8-5ad582299bc5 MEDIUM 5.3 The Stitch Express plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.9.1… wordfence
fb6f9e06-66c1-44db-88cd-008e39dddedd
< 2.19.18
MEDIUM 5.3 The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to unauthorized… wordfence
fb5cb7ce-127a-4f9a-b52e-1e957560ca55
< 2.3
MEDIUM 5.3 The Slider a SlidersPack plugin for WordPress is vulnerable to unauthorized modification of data due to missing capabili… wordfence
fb545bba-7bd8-4410-93e9-17194a3b5460
< 1.4.7
MEDIUM 5.3 The VW School Education theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
fb19fd06-7b2c-41a1-a470-230da7ce944d
< 4.7.2
MEDIUM 5.3 The Malware Scanner plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 4.7.… wordfence
fb102891-b4a8-4089-b70c-43866ad85b7b
< 2.11.4
MEDIUM 5.3 The Antispam Bee plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.11.3 … wordfence
fb057a32-0027-4ca6-b65e-8634509c9a81
< 2.2.79
MEDIUM 5.3 The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordP… wordfence
fadc1374-fe4d-414a-af84-1a4de5b89807
< 2.33.1
MEDIUM 5.3 The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… wordfence
fac8669b-84c0-4388-8e3e-cd1be2ae5ba3
< 3.5.2
MEDIUM 5.3 The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty p… wordfence
faa9ad87-44b2-47b3-a05c-52e59af7255a
< 2.3.1
MEDIUM 5.3 The WP Meta and Date Remover plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
fa918a65-0021-4c32-9f6d-d978926c3ef3
< 6.9.8
MEDIUM 5.3 The Email Before Download plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
fa8a1e98-8e5b-49d3-8378-f7b5be92f205
< 3.9.7
MEDIUM 5.3 The ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerabl… wordfence
fa7cf13c-a13f-4302-9ba4-a53c552fe59b
< 0.21.15
MEDIUM 5.3 The Tainacan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a… wordfence
fa781206-57d7-47d4-9cd8-20ae38eeef83
< 3.8.3.3
MEDIUM 5.3 The Pie Register Premium plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
fa5f1c1b-fb20-4106-a9d3-6e4e304d30be
< 3.0.3
MEDIUM 5.3 The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
fa4ac740-8f57-4d0c-8e04-dcddeeb3c89e
< 2.5.1.4
MEDIUM 5.3 The Permalink Manager Lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… wordfence
fa3501a4-7975-4f90-8037-f8a06c293c07
< 7.6.22
MEDIUM 5.3 The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6… wordfence
fa27f37a-11d3-4f65-a86d-9c45c092b537 MEDIUM 5.3 The ACF to REST API plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl… wordfence
fa22210e-cf91-4486-b4e0-9e871f713e5c
< 1.7.9
MEDIUM 5.3 The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
fa2102b3-408b-4278-b542-b5d30685960d
< 1.20.0
MEDIUM 5.3 The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPre… wordfence
f9fe8ff7-32c7-4c40-8e70-48cd7a9910ec
< 10.1.3
MEDIUM 5.3 The Montonio for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
f9f5aa00-58d3-4b22-af15-1dfd1d70690b
< 7.6.4
MEDIUM 5.3 The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress i… wordfence
← Prev 1100 1101 1102 1103 1104 1105 1106 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top