πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1104 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f9f3250f-39a1-4ba1-b9a2-222926635ca0 MEDIUM 5.3 The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and inclu… wordfence
f9d11597-0bea-4f58-9dac-b4b82d07c2f6
< 4.4.0
MEDIUM 5.3 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to unauthorized access due … wordfence
f9cff7c4-7dc0-440b-bb1c-1087144d1ccf
< 1.1.1
MEDIUM 5.3 The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to unau… wordfence
f9be7798-31ac-4692-a6ac-ae7f129bcd6d
< 3.7.3
MEDIUM 5.3 The Premmerce Product Filter for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
f9af0471-adb0-42c6-8a7b-da7d28e5e3aa
< 2.2.1
MEDIUM 5.3 The weDocs plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
f989558e-8ba5-4c8e-b099-e919ebe966ac
< 1.1.5
MEDIUM 5.3 The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
f9611732-67aa-4940-8df1-c0ed7baad985
< 3.2.50
MEDIUM 5.3 The Download Manager plugin for WordPress is vulnerable to IP Blocking Bypass in versions up to, and including, 3.2.49 d… wordfence
f9575875-0f0f-4069-87d1-9ed573a7c3d7
< 5.3.2
MEDIUM 5.3 The Advanced File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
f9566fdd-c4ad-4971-b23b-bcf76c8b5cef
< 2.0.3
MEDIUM 5.3 The WaMate Confirm – Order Confirmation plugin for WordPress is vulnerable to unauthorized access in all versions up t… wordfence
f8ddb7df-7f74-486d-a55f-9e2d1e91f112
< 1.6.2
MEDIUM 5.3 The SearchWP Live Ajax Search plugin for WordPress is vulnerable to arbitrary post title disclosure in versions up to, … wordfence
f8cd9f1a-84e5-432f-a07d-f5941b8d9dda
< 7.1.2
MEDIUM 5.3 The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure … wordfence
f894ce75-168c-4baa-8cae-d2e7f1a0a9ab
< 6.4.21
MEDIUM 5.3 The Business Directory Plugin for WordPress is vulnerable to authorization bypass due to a missing authorization check i… wordfence
f889342e-03fb-44eb-b5cb-acf115a526c3
< 1.1.3
MEDIUM 5.3 The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data… wordfence
f87efb65-b53b-4e9c-b933-9303461487a3
< 3.2.4
MEDIUM 5.3 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to a bypass in all versions up to, a… wordfence
f86602f7-8e19-4728-b614-263c36bda565 MEDIUM 5.3 The InWave Jobs plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
f8650a2e-346f-45fb-b5f5-ee99a470b2fc
< 1.9.4
MEDIUM 5.3 The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3… wordfence
f85478c4-ea66-4bca-b501-2e55425396f7
< 4.16.3
MEDIUM 5.3 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Payment Bypass in all vers… wordfence
f84ddc83-2079-45b9-8354-51094581b1f8
< 4.3.9
MEDIUM 5.3 The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized … wordfence
f8457aeb-867b-4185-8271-a5452b7c5365
< 3.0.11
MEDIUM 5.3 The Animator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… wordfence
f83a6631-ff6c-422e-8b6c-49576fadb89f
< 2.6.8
MEDIUM 5.3 The WP Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an… wordfence
f82aca0a-a75f-4766-a808-004d13c77bac
< 1.4.110
MEDIUM 5.3 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access due… wordfence
f823ad14-754e-4fed-b991-6ee8594c7f86
< 1.7.4
MEDIUM 5.3 The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
f81d7451-352b-446e-965b-9b51031844ed
< 1.2.1
MEDIUM 5.3 The Opal Woo Custom Product Variation plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient … wordfence
f810cc65-5a19-4ad7-a6b6-41a9b4f30f4c
< 3.6
MEDIUM 5.3 The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all v… wordfence
f80fa8b3-f345-4b3f-8a16-ee9f19b07a0b
< 5.1.4
MEDIUM 5.3 The SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule P… wordfence
← Prev 1101 1102 1103 1104 1105 1106 1107 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top