🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1126 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d27ef0b4-266f-47b8-a7aa-ddff5adaac7a MEDIUM 5.3 The Admin Post Navigation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includin… wordfence
d2547355-cfc0-4a87-9bab-32753bd456ad
< 1.8.4
MEDIUM 5.3 The iPanorama 360 WordPress Virtual Tour Builder plugin for WordPress is vulnerable to unauthorized access of data due t… wordfence
d24f42c0-5fd4-4960-b529-10cd5d9e7379
< 5.2.5
MEDIUM 5.3 The WooCommerce Dropshipping Premium plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… wordfence
d234212a-2019-477d-81d1-b2acc2321055
< 2.7.14
MEDIUM 5.3 The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
d212c19d-fca9-4daf-95f4-5b3ac302e817
< 1.6.3
MEDIUM 5.3 The LoginPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability checks in versions… wordfence
d20ff1a8-8794-41e1-9e66-1cda90f9ff77
< 7.2.1
MEDIUM 5.3 The EWWW Image Optimizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… wordfence
d20e1313-579c-4b31-aa2a-090b0b05fb67
< 0.69
MEDIUM 5.3 The Protección de datos – RGPD plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
d1f41400-5c59-444d-9c1e-121e83449521
< 7.5.2
MEDIUM 5.3 The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of … wordfence
d1efe450-d081-421e-95c3-f2d79c328a33 MEDIUM 5.3 The Easy Student Results plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on… wordfence
d1e947a7-7449-4795-8016-b34811c0c369 MEDIUM 5.3 The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Insecure Direct Object Reference in vers… wordfence
d1d32a1d-076e-4a93-a678-145d154edb3a
< 2.0.1
MEDIUM 5.3 The Order Limit for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
d1c7df8e-2f82-4474-88ef-8c8ddaeb4656 MEDIUM 5.3 The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is … wordfence
d1c4052b-e8e9-47da-8a36-c67f16ab2553
< 2.1
MEDIUM 5.3 The Leadinfo plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
d199e597-64ed-4dcc-a153-b5c8e4e9e93d
< 2.6.13.1
MEDIUM 5.3 The JetElements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on a… wordfence
d187a8d6-fa81-45c6-a107-f8b96b130e6c
< 4.0.3
MEDIUM 5.3 The WooCommerce AWeber Newsletter Subscription plugin for WordPress is vulnerable to unauthorized modification of data d… wordfence
d169fa88-3f75-47a0-93df-dd3550b59278 MEDIUM 5.3 The Epeken All Kurir for Woocommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and inc… wordfence
d162559e-fb6c-40e2-9fc3-49370f9a779e
< 1.27.13
MEDIUM 5.3 The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… wordfence
d157c63d-824d-4ad0-841c-fdca63b37eb4
< 3.2.7
MEDIUM 5.3 The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
d145d0af-e364-4cc3-af4f-03117eb34637 MEDIUM 5.3 The My Custom CSS PHP & ADS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includ… wordfence
d140c42b-09d9-41aa-8a6a-0fa4b4404b11 MEDIUM 5.3 The Ryviu – Product Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
d12067ce-d2a1-4426-995c-590285500094 MEDIUM 5.3 The Fitness Trainer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
d1123d28-56a7-4bf8-92ce-2749e4676623
< 5.5.13
MEDIUM 5.3 The Ivory Search plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
d10364ed-179d-4506-a6f0-42b03c005242
< 2.0.5
MEDIUM 5.3 The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘siteorigi… wordfence
d1000b18-ce1f-4803-98ea-c6b42ccc9f54
< 1.2.5
MEDIUM 5.3 The Perfect Portfolio theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
d0f216fc-7073-42da-a3cc-7452fa9775bd
< 2.1.9
MEDIUM 5.3 The ShopBuilder – Elementor WooCommerce Builder Addons plugin for WordPress is vulnerable to Sensitive Information Exp… wordfence
← Prev 1123 1124 1125 1126 1127 1128 1129 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top