πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1108 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f33bcc8d-3d21-4de8-87ac-a5e334bb641d
< 2.0.1
MEDIUM 5.3 The WPGraphQL Smart Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to 2.0.1 (exclus… wordfence
f3341c29-a69e-4618-a8a5-11f4141ff88f MEDIUM 5.3 The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi… wordfence
f32ae42d-dd1f-41d7-8ae4-ddec56d78ae6
< 3.9.9
MEDIUM 5.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content… wordfence
f30af3c4-82be-40d5-be9f-82631b8f3ee2
< 1.0.8
MEDIUM 5.3 The Simple History plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.0.7… wordfence
f30810d4-415c-4001-919d-eac753715474
< 4.3.4
MEDIUM 5.3 The Estatik Real Estate Plugin plugin for WordPress is vulnerable to mail relay in all versions up to 4.3.4 (exclusive).… wordfence
f304b0c2-ddea-4638-8a0b-c1483c944d30
< 1.1.3
MEDIUM 5.3 The Majestic Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
f2e8062a-d185-4834-a8cf-1f505ee2e91e
< 1.5.6.3
MEDIUM 5.3 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
f2d69d59-390d-4f3c-96ba-487707cac7a6
< 6.9.5
MEDIUM 5.3 The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Sensitive Information Exposure in al… wordfence
f2c70d5f-beb3-480e-8ea8-c3ab01ce5a20 MEDIUM 5.3 The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin… wordfence
f2c3b646-d865-4425-bc8f-00b3555a3d74
< 8.5.7
MEDIUM 5.3 The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthoriz… wordfence
f2bcaff9-bf04-4d8e-9422-c433264067ff
< 4.0.25
MEDIUM 5.3 The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorize… wordfence
f2aa33cc-c1c4-42d4-9c2f-54648426ee4b
< 11.1.1
MEDIUM 5.3 The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and inc… wordfence
f28d7659-9244-4da8-97e9-4539d7d874f7
< 1.0.72
MEDIUM 5.3 The Polls CP plugin for WordPress is vulnerable to content injection in all versions up to, and including, 1.0.71. This … wordfence
f28c47e6-a37d-4328-afb2-6a9e6b3fe20a MEDIUM 5.3 The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposu… wordfence
f2856011-0080-4786-9ef0-14f323d54962 MEDIUM 5.3 The Sandwich Adsense plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
f26b0dc2-2b24-46e6-a7e8-f87e970df042
< 1.4.1
MEDIUM 5.3 The WP Directory Kit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
f265955d-a209-4193-9fb8-962b1b562249
< 5.4
MEDIUM 5.3 The Apptivo Business Site CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
f25dcd7e-8fb1-471e-bd22-782409de45c4
< 1.17.2
MEDIUM 5.3 The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to un… wordfence
f25d0409-dbca-4c5a-9f43-fc03e5307d0f
< 1.5.1.3
MEDIUM 5.3 wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-… wordfence
f23bb22c-2f7b-4940-b0bc-1e5f2b8d0ed2
< 1.0.1
MEDIUM 5.3 The Byteflows Travel & Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all version… wordfence
f23ba80e-94d7-40a1-beb8-da9ec0c9f7d7
< 2.4.5
MEDIUM 5.3 The EventON – Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
f2122fa2-0500-4c4e-aec5-eb440e8cc585
< 5.5.79
MEDIUM 5.3 The Data Access plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
f1fa1999-685c-4b68-927d-617abf9143d7
< 2.9.1
MEDIUM 5.3 The Premium Addons PRO plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and inclu… wordfence
f1e5438f-1309-4d39-a9b4-cda27b652d93
< 2.0.8
MEDIUM 5.3 The E-cab Taxi Booking Manager for Woocommerce plugin for WordPress is vulnerable to unauthorized access in all versions… wordfence
f1ad41b4-c97b-4b3d-a82d-b39570ffe82f
< 1.0.25
MEDIUM 5.3 The Agency Toolkit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
← Prev 1105 1106 1107 1108 1109 1110 1111 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top