πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1116 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e52e35db-22e8-42e1-88a6-37ca9a1df7d4 MEDIUM 5.3 The WooCommerce Manager – Customize and Control Cart page, Add to Cart button, Checkout fields easily plugin for WordP… wordfence
e4deb62a-1a75-4951-a0a0-297dd17276d3
< 3.1.40
MEDIUM 5.3 The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin… wordfence
e4dcedcc-2878-47b2-99f0-ecba2cc33b69
< 5.6.2
MEDIUM 5.3 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorizatio… wordfence
e4b4d08a-9f2c-4c81-bef7-14dced7af282
< 2.0.0
MEDIUM 5.3 The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPres… wordfence
e4ae2b7d-e48d-4880-9202-6e564a3b404f
< 1.7.29
MEDIUM 5.3 The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Sensitive Inf… wordfence
e4a8a202-e44a-4874-9e7a-c8224edd8591
< 3.4.0
MEDIUM 5.3 The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow u… wordfence
e48142c2-3688-4638-abfc-1e191f362055
< 1.12.0
MEDIUM 5.3 The Masteriyo - LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … wordfence
e4482f92-024d-402d-9cf3-c4709f23baf0
< 3.9.8
MEDIUM 5.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access due to … wordfence
e4457df6-81ca-4149-bcca-623cff2cbeef
< 2.2.3
MEDIUM 5.3 The WooCommerce Product Vendors plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
e43f61e5-4b74-47d7-ad54-a8df682d1f75
< 2.0.16
MEDIUM 5.3 The Addonify – WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
e4383f41-bd08-4fab-9491-4cf9f7326300
< 2.5.0
MEDIUM 5.3 The Broken Link Checker | Finder plugin for WordPress is vulnerable to modification of data due to a missing capability … wordfence
e4376069-42c6-4bb6-a9df-93564da836b2
< 8.9.6
MEDIUM 5.3 The Geo Controller plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu… wordfence
e4358e2a-b7f6-44b6-a38a-5b27cb15e1cd
< 6.1.8
MEDIUM 5.3 The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of… wordfence
e43234ac-d9e3-41d1-a833-bfbe2ac79d44
< 2.7.1
MEDIUM 5.3 The Food plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in ve… wordfence
e42cef39-35d7-4ef5-99da-c34d3ccab667
< 2.0.8
MEDIUM 5.3 The TypeSquare Webfonts plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… wordfence
e421cb35-e9f4-43f3-a39e-d51d197bc279
< 3.7.2
MEDIUM 5.3 Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit a… wordfence
e3f665b8-fbd5-4100-baf6-3fa99332a5dc
< 14.0
MEDIUM 5.3 The VS Contact Form plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 13.9. … wordfence
e3e99032-2e71-45bd-99a6-ad0a93c39bc0
< 1.7.65
MEDIUM 5.3 The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Path Traversa… wordfence
e3e682fb-e821-45cb-a087-d97d42a3743e MEDIUM 5.3 The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. Th… wordfence
e3cb52a2-260b-4f3a-8964-cd2fdf75c0b1
< 1.117.5
MEDIUM 5.3 The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is v… wordfence
e3c52da7-ddfb-4c47-b8d2-2e1db6ec3946
< 1.3.9
MEDIUM 5.3 The Stop User Enumeration plugin for WordPress is vulnerable to User Enumeration in versions up to, and including, 1.3.8… wordfence
e3c52d6e-b3f4-4ba8-aee4-b9f11704e1de
< 2.2.2
MEDIUM 5.3 The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an impr… wordfence
e3b3ce65-b226-4b93-ab0c-984f774454f7
< 2.17.1
MEDIUM 5.3 The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Sensitive Inform… wordfence
e3a7e0b6-dc6d-4e3a-bb05-12d6ace330df MEDIUM 5.3 The BigCommerce For WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to… wordfence
e39d3ec1-b1a5-4176-88ac-432d91dbf621
< 1.1
MEDIUM 5.3 The Leadinfo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… wordfence
← Prev 1113 1114 1115 1116 1117 1118 1119 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top