πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1109 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f188a5e6-699e-4e1a-b4e4-7fb4056b0bee
< 8.8.2
MEDIUM 5.3 The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive … wordfence
f162e046-a7d3-4f2c-899d-6c46cb92c8ee
< 17.3
MEDIUM 5.3 The Yoast SEO plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 17.2 via t… wordfence
f125a9d4-7399-47ae-9b5d-4cfe12c4c177
< 3.0.0
MEDIUM 5.3 The Sahifa theme for WordPress is vulnerable to Full Path Disclosure in versions up to, and including, 2.4.0 via the 'ca… wordfence
f11926c8-2b31-4ad5-9fd0-225071a91b2a
< 4.2
MEDIUM 5.3 The Login With Ajax plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an un… wordfence
f0e2d690-7562-438a-aa9f-d2711ddd7d2c
< 3.26.7
MEDIUM 5.3 The Wishlist Member plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … wordfence
f0b6c41d-833e-4ad4-bdb6-c38fef3eb7f4
< 2.5.3
MEDIUM 5.3 The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versi… wordfence
f0a31fee-ccc2-4c3b-b198-6cb750188113
< 1.7.24
MEDIUM 5.3 The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability c… wordfence
f09d7c11-3e4d-431d-91f2-0b77f51974f6
< 1.1.4
MEDIUM 5.3 The Leadpages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
f09d722e-e4eb-4d0b-844f-3a687eb454bf
< 6.2.6
MEDIUM 5.3 The miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) plugin for WordPr… wordfence
f093f44e-972c-407a-ab6b-4dd8acda5b95 MEDIUM 5.3 The Conditional CAPTCHA plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.0.0.… wordfence
f06f0492-c03d-44d7-9441-4d79f89e5c1f
< 1.1
MEDIUM 5.3 The Appius theme for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.0. This coul… wordfence
f0691a2a-734e-4726-97a1-9e0c796c2fb5
< 3.7.40
MEDIUM 5.3 WordPress Core is vulnerable to Information Disclosure of in versions up to 6.0.3. When the post by email functionality … wordfence
f062ef94-e558-478e-bbfd-06616aeb566b
< 3.0.0
MEDIUM 5.3 The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This i… wordfence
f04dee5b-d16f-4ef0-88a4-1567e2287bd5
< 4.12
MEDIUM 5.3 The Category Discount Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
f04765fb-7144-4e6f-ab5a-5a06b45dbb17
< 1.6.5
MEDIUM 5.3 The Security Optimizer – The All-In-One Protection Plugin plugin for WordPress is vulnerable to IP Allowlist Bypass in… wordfence
f03dfbd4-b34a-46ab-b8aa-e37fb0321e8e MEDIUM 5.3 The SendPress Newsletters plugin for WordPress is vulnerable to unauthorized modification of due to a missing capability… wordfence
f0343861-a376-43ea-826e-277c2a5ea635
< 3.1.5
MEDIUM 5.3 The JetFormBuilder β€” Dynamic Blocks Form Builder plugin for WordPress is vulnerable to content injection in all versio… wordfence
f008d502-e554-489d-bb97-fed18fa6547d
< 1.9.2
MEDIUM 5.3 The Patreon WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
f0077624-c111-468f-ae24-d730642b676c
< 14.4.0
MEDIUM 5.3 The BuddyPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
f00763e2-f5a0-495b-949d-0012f278d4ed MEDIUM 5.3 The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to unauthorized access due t… wordfence
eff4cb35-492b-448a-8d16-b9210917c567
< 2.8
MEDIUM 5.3 The WP Simple HTML Sitemap plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
efe7c5d6-80ee-4214-b179-805df79ce1fc
< 1.12.19
MEDIUM 5.3 The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin f… wordfence
efe4223a-5c1a-401e-a46b-0278e96d2d71
< 4.5.0
MEDIUM 5.3 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in … wordfence
efc53d78-a664-48d0-a752-00c56b3f792f MEDIUM 5.3 The No CAPTCHA reCAPTCHA for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to … wordfence
efb6fc8e-5eed-4751-881f-0600c817ba6a
< 2.0.1
MEDIUM 5.3 The Simple GDPR Cookie Compliance plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
← Prev 1106 1107 1108 1109 1110 1111 1112 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top