πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1125 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d42bf247-413b-4458-84f3-f503c7af907d
< 1.0.33
MEDIUM 5.3 The Secure Card Gateway for ePay Paycenter (Piraeus Bank) plugin for WordPress is vulnerable to unauthorized access due … wordfence
d41f506a-b243-41e2-a67e-697fc34fba2e
< 2.5.4.1
MEDIUM 5.3 The Bookit β€” Booking & Appointment Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
d3f3fc78-0255-4c0a-8ee0-c2ccea28929f
< 1.0.13
MEDIUM 5.3 The Chama plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
d3e194c0-b35a-496b-b31a-666334312f20
< 1.4.2
MEDIUM 5.3 The Paid Memberships Pro – Payfast Gateway Add On plugin for WordPress is vulnerable to Sensitive Information Exposure… wordfence
d3adb4ba-cabd-4b16-bda6-5d5fc7582d5f
< 2.1.2
MEDIUM 5.3 The Wbcom Designs – Private Community for BuddyPress plugin for WordPress is vulnerable to unauthorized access due to … wordfence
d3aa1f74-6372-4abe-894b-07ad3e81ea81 MEDIUM 5.3 The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and i… wordfence
d39ec46d-58c4-40e4-b94a-e7a9fc99291a
< 3.7.1
MEDIUM 5.3 The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct O… wordfence
d396e47a-cabe-4498-9269-d67bdeb0c570
< 1.1.4.6
MEDIUM 5.3 The OptinMonster plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.4.5 v… wordfence
d390186e-b6a3-4c9c-8065-2ac4fff9be37
< 6.0.12
MEDIUM 5.3 The Kirki plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
d38fd7d0-0d04-4d60-bb5b-7a68758df83c
< 2.4.1
MEDIUM 5.3 The GTM Kit – Google Tag Manager & GA4 integration plugin for WordPress is vulnerable to Sensitive Information Exposur… wordfence
d36e869a-5bd4-4f59-8e28-01fa586024c5
< 2.2.22
MEDIUM 5.3 The Super Progressive Web Apps plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … wordfence
d35faf39-4882-4393-9b77-57dc45ac9d04
< 4.7.0
MEDIUM 5.3 The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carous… wordfence
d34ba8b3-e8a8-4810-a0d9-8781bc7d1201
< 2.0.1
MEDIUM 5.3 The Post/Page Copying Tool to Export and Import post/page for Cross site Migration plugin for WordPress is vulnerable t… wordfence
d34701a0-c745-441c-8d6c-7befc877f8d0
< 1.7.2
MEDIUM 5.3 The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authoriza… wordfence
d3457b87-c860-4cf2-ac3d-2c6521b629ea
< 1.3.88
MEDIUM 5.3 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to … wordfence
d33b83d5-cfc0-48b6-a54e-1ae8ac52aae1
< 1.0.8
MEDIUM 5.3 The Voidek Employee Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
d3184996-655c-41d5-a3c5-6b36fbff58dc
< 6.4.6.1
MEDIUM 5.3 The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up … wordfence
d317f2c7-06f3-4875-9f9b-eb7f450aa2f4
< 2.0.5
MEDIUM 5.3 The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2… wordfence
d3103345-ce26-4bb1-898f-764ab6cf0ea0
< 24.7.0
MEDIUM 5.3 The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
d300288e-f100-4c02-ba65-d728e3b1522e
< 8.1.2
MEDIUM 5.3 The Seers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on m… wordfence
d2d50c64-f4e2-4a5a-b37f-bbb636ee468d
< 1.2.43
MEDIUM 5.3 The Time Slots Booking Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
d2d040d5-ffcb-4ab9-8606-c18a3d2ccad9
< 3.6.3
MEDIUM 5.3 The Easy WordPress Funnel Builder To Collect Leads And Increase Sales – WPFunnels plugin for WordPress is vulnerable t… wordfence
d2b74b9d-b296-4d3b-936f-419dad502d79
< 1.1.9
MEDIUM 5.3 The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized access… wordfence
d2b3279b-fd39-4c34-92e8-57d309f37a93
< 1.10.9
MEDIUM 5.3 The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX acti… wordfence
d2994fbb-29b0-4725-a046-edeca4bcbcd7
< 2.2.8
MEDIUM 5.3 The EventON plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the g… wordfence
← Prev 1122 1123 1124 1125 1126 1127 1128 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top