πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1124 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d5fd2c48-c114-4bd4-9a38-bc0d733f65f3
< 1.2.7
MEDIUM 5.3 The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable… wordfence
d5cfe324-ab86-454a-a016-5e3d0e4df936
< 4.3.6
MEDIUM 5.3 The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to unauthorized access due to a m… wordfence
d5cf5fd2-58c7-42d0-948f-95764647630b
< 1.10.0.5
MEDIUM 5.3 The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress i… wordfence
d5c652be-ea24-4fbe-aa88-ea1f8814d34a
< 3.3.53
MEDIUM 5.3 The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
d5b89ef5-2bf1-4fc0-9127-5c2a18c96caa
< 1.3
MEDIUM 5.3 The Setup Default Featured Image plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
d5a51c22-c4ca-4897-ad7e-c5df00b07fe0
< 1.10.2.1
MEDIUM 5.3 The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress i… wordfence
d5a135cf-99b6-4e9e-b66a-1b547501ce9f
< 269.3
MEDIUM 5.3 The ConveyThis plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
d58490a9-c48f-4693-8e42-70486563a731
< 3.0.7
MEDIUM 5.3 The Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor plugin for WordPress is vulnerable to Sensitive Info… wordfence
d57c3934-61b9-419d-af11-65f5f26284e3
< 1.6.8
MEDIUM 5.3 The WP-Record plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
d55f10f3-5484-4b90-80da-3d91f409fe04
< 4.10.45.decaf
MEDIUM 5.3 The Event Espresso 4 Decaf plugin for WordPress is vulnerable to bypass of a plugin feature in versions up to, and inclu… wordfence
d554874d-a681-4355-845c-5df8d66825fb
< 2.2.8
MEDIUM 5.3 The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… wordfence
d553aab2-d441-46d6-9c01-5dcfdc48674f
< 1.28
MEDIUM 5.3 The Advanced Google reCaptcha plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.2… wordfence
d535c069-cfa3-4c41-9a01-b4c4e7c75764
< 1.3.0
MEDIUM 5.3 The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (Re… wordfence
d52ec5ce-b193-4908-8927-44592d1a2f3d
< 2.11.11
MEDIUM 5.3 The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to unauth… wordfence
d503de5f-ba13-4c51-b514-15f2e7b2752b
< 2.6.4
MEDIUM 5.3 The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Sensitive Information Expos… wordfence
d5031631-9f12-47d3-997d-4418d348ab40
< 1.0.18
MEDIUM 5.3 The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.17. … wordfence
d502e617-a59f-4385-b050-3702a1b1ed7e
< 1.6.15
MEDIUM 5.3 The BoldGrid Easy SEO – Simple and Effective SEO plugin for WordPress is vulnerable to Information Exposure in all ver… wordfence
d4a5c931-16f8-41b6-b4b6-567aa6c6c90e
< 5.1.3
MEDIUM 5.3 The All-In-One Security plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, … wordfence
d4918bc5-5d92-4363-abd5-69f2c9a46543
< 2.7.17
MEDIUM 5.3 The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
d488cfef-8ee7-483a-94f2-c172e5576005
< 1.5.1
MEDIUM 5.3 The SSU plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the… wordfence
d48899b9-b3b3-45d7-b7e1-6a8560becb0b
< 1.6.11.1
MEDIUM 5.3 The Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
d47d582d-7c90-4f49-aee1-03a8775b850d
< 1.5.10
MEDIUM 5.3 The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. T… wordfence
d47abf24-bced-44d8-aa99-42f25a938f46 MEDIUM 5.3 The IDonatePro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
d463ca92-202b-47de-9d6a-cee4453d33b9
< 2.5.4
MEDIUM 5.3 The CatFolders plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
d44184d0-2874-483b-9855-37a4f9cd141f
< 2.8.158
MEDIUM 5.3 The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable t… wordfence
← Prev 1121 1122 1123 1124 1125 1126 1127 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top