πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1123 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d84cf972-be7e-497c-b360-2ea491e44ad6
< 2.8
MEDIUM 5.3 WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensi… wordfence
d830c2eb-16e8-425c-ac46-a467a2fd0133
< 1.2.1
MEDIUM 5.3 The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, … wordfence
d8096f3c-e1a9-424f-af10-3e80212db985
< 2.7.3
MEDIUM 5.3 The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due… wordfence
d7e41753-2dbf-4afa-b61e-e617be2c4dc2
< 1.16.18
MEDIUM 5.3 The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to unau… wordfence
d7d8d1e9-04d6-43f0-86a1-386cc1255802
< 1.2.1.2
MEDIUM 5.3 The Toolset Types plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.1.1 d… wordfence
d7d08bfd-9861-4e21-a696-25b00233ad94
< 7.2.1
MEDIUM 5.3 The EWWW Image Optimizer for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including,… wordfence
d7ccbe77-939f-4828-9b86-40cd654cfce6
< 1.8.1.8
MEDIUM 5.3 The Charitable plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
d7b15198-8f44-4390-862b-35d41eb8a854
< 3.1.5
MEDIUM 5.3 The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modificatio… wordfence
d7968c70-0a66-4067-9864-105df483cd42 MEDIUM 5.3 The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
d76b6355-a1c5-41a0-b3b6-ee13e5490314
< 2.0.6
MEDIUM 5.3 The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information… wordfence
d738be73-2573-4fb8-b6f0-768a08628265
< 2.35.18
MEDIUM 5.3 The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… wordfence
d734893b-fe81-42e0-99f5-153138953287 MEDIUM 5.3 The Institutions Directory plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
d731f7bf-d2de-4f5f-8c4a-627713bec348
< 8.3.5
MEDIUM 5.3 The WP Customer Area plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 8.3.4. T… wordfence
d6ec0bfd-6b3f-4de5-a7ea-73e35339202c
< 3.2.4
MEDIUM 5.3 The Accept Stripe Donation and Payments – AidWP plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
d6e87973-6001-439b-aef8-805ba4275d27
< 3.11.5
MEDIUM 5.3 The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to arbitrary f… wordfence
d6c78f4b-97e5-4581-a776-4edb04871de8
< 20251210
MEDIUM 5.3 The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Open … wordfence
d6c1ba13-9c1a-4ba8-b481-677bf0b1534b MEDIUM 5.3 The ListingPro theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
d6bb8b44-a5b4-4909-9e2e-7123ae0737c9 MEDIUM 5.3 The Get Cash plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
d6a99806-cb8f-4c12-86ed-2cdbb45ba873 MEDIUM 5.3 The WP Headless CMS Framework plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, a… wordfence
d67cd96b-6fec-44db-be50-395bed199e9b
< 2.2
MEDIUM 5.3 The Meta Slider plugin for WordPress is vulnerable to full path disclosure in versions up to, and including, 2.1.6. This… wordfence
d672fcb9-6607-477e-b168-546669886ea4
< 5.2.1
MEDIUM 5.3 The Captcha by BestWebSoft for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 5.2.0. This m… wordfence
d665df2d-5217-4a23-9278-5b88162f7d13
< 1.5.88
MEDIUM 5.3 The Appointment Hour Booking plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, … wordfence
d62bd71c-3d08-4767-b471-a1d5a17fe6ba MEDIUM 5.3 The Aramex Shipping WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and in… wordfence
d625881a-4789-4fc4-94b7-5ab6c6b39092 MEDIUM 5.3 The DesignThemes LMS Addon plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
d60540ec-e176-42f3-a987-141a9aa184c6
< 4.16.6
MEDIUM 5.3 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access due to… wordfence
← Prev 1120 1121 1122 1123 1124 1125 1126 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top