πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1117 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e39c4730-f5b3-4554-9e4f-bbbbcb41cf61
< 2.12
MEDIUM 5.3 The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
e3991601-a96c-4f98-a0f6-04a134ec6feb
< 3.3.26
MEDIUM 5.3 The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… wordfence
e36df7b7-fcbc-4e5d-812c-861bfe8abb55
< 1.3.12
MEDIUM 5.3 The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a … wordfence
e36056bf-4e90-4c5e-8c6a-ab3ae7ba426f
< 5.5.5
MEDIUM 5.3 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to HTML Injection in al… wordfence
e3541aba-fc78-4395-88ca-4ecbf84d5b90 MEDIUM 5.3 The WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics plugin for WordPress is vulnerable… wordfence
e34ac4aa-65c5-43d7-9b77-d4c6068722f1 MEDIUM 5.3 The Publish approval plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
e3491f9d-78ea-4f3a-81d2-26baed6f3ab7
< 5.3.4
MEDIUM 5.3 The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
e3447438-1624-451a-a50c-981021399198 MEDIUM 5.3 The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request… wordfence
e31ecd7e-95ea-4a35-ae6d-ad3c61b1cae9
< 1.8.17.0
MEDIUM 5.3 The WP Mailster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… wordfence
e30eea7a-4711-4a3e-928d-eeca9e3b43bf MEDIUM 5.3 The Wiremo plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
e2f8cdd3-f873-42bd-9891-a63a398df846
< 2.3.2
MEDIUM 5.3 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to email spoofing in versions up to, and i… wordfence
e2f61393-fe09-4488-b8d5-12e2be16c1e2
< 4.0.5
MEDIUM 5.3 The Depicter β€” Popup & Slider Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
e2f19051-fe80-469c-a514-ec3a848a4015
< 2.9.3
MEDIUM 5.3 The Graphene theme for WordPress is vulnerable to unauthorized access of data via meta tag in all versions up to, and in… wordfence
e2e96557-7341-4da9-81ca-2bd17a85559e
< 2.2.4
MEDIUM 5.3 The Frontend Dashboard plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i… wordfence
e2c9f6a5-8698-4452-bf0a-c1d796b2fdad
< 5.2.46
MEDIUM 5.3 The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.… wordfence
e2a663f2-212f-4c17-a192-ee8982899fa7
< 5.6.8
MEDIUM 5.3 The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
e2945971-80c6-44a2-bc65-1243af365692
< 1.6.0
MEDIUM 5.3 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
e26dd66f-e0fe-47c7-a45c-fb06b5bcc612
< 5.2.20
MEDIUM 5.3 The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to unauthorized access due to … wordfence
e25fd68a-a4aa-4539-ba1a-de1d7b28c7ff MEDIUM 5.3 The Photography theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
e25015c9-d764-44b2-ad54-edf5d248e56c
< 2.6.1
MEDIUM 5.3 The Email Customizer for WooCommerce | Drag and Drop Email Templates Builder plugin for WordPress is vulnerable to Sensi… wordfence
e24339c3-f8f8-4357-9717-a3077420603a
< 3.4.1
MEDIUM 5.3 The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability. wordfence
e23dcadf-5858-4b8e-8b48-d3133c40cd89
< 2.2.76
MEDIUM 5.3 The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel plugin for WordPress is vulnerabl… wordfence
e20feb23-f78e-42e7-8922-e7cf37dbdcb1 MEDIUM 5.3 The Shortcodes by Angie Makes plugin for WordPress is vulnerable to missing authorization due to a missing capability ch… wordfence
e207f1a3-2ca5-46d1-91a9-89652451266c
< 2.13.5
MEDIUM 5.3 The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPr… wordfence
e20082a0-dca6-4a26-919f-d59752dfbe90
< 2.18.0
MEDIUM 5.3 The Visual Portfolio, Photo Gallery & Post Grid plugin for WordPress is vulnerable to CSS injection via the REST API in … wordfence
← Prev 1114 1115 1116 1117 1118 1119 1120 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top