πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1127 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d0d0184a-6aa1-41af-8b18-6bab3b64f42f
< 2.3.6
MEDIUM 5.3 The ElementCamp plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
d0a8c924-04f7-47e7-ba84-f090abc7279a MEDIUM 5.3 The Scalenut plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
d0a818b6-5e25-4c96-8757-b8593c713923
< 3.3.31
MEDIUM 5.3 The Instantio β€” Side Cart & One-Page Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Informat… wordfence
d0a55af3-108a-4a7b-ac9e-ef7c9e3a3acd
< 1.9.0
MEDIUM 5.3 The Simple WP Events plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… wordfence
d09d8ac7-67f4-490b-8d09-6811f132fede
< 5.7.14
MEDIUM 5.3 The Email Subscribers & Newsletters plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
d09a0b62-6556-4be5-a6f2-0cb0edcced3b
< 2.25.3
MEDIUM 5.3 The GiveWP for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.2. This is d… wordfence
d05f7b77-382b-422a-8096-f47291f4dc45
< 9.7.6
MEDIUM 5.3 The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper author… wordfence
d04bae24-f513-4106-873e-9997d656b71a MEDIUM 5.3 The WebP Conversion plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
d0240b35-72d0-4943-84cd-5d1574609b36
< 1.18.0
MEDIUM 5.3 The Popup Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1… wordfence
d01f4e67-a463-4973-97b1-41a64398686a
< 7.8.2
MEDIUM 5.3 The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access… wordfence
d0189895-91d6-48ea-86cb-9a2db9de3d9a
< 2.0.0
MEDIUM 5.3 The WEDOS Global plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
d0077130-f604-4400-aa2b-e8a1f06cd475
< 1.4.7
MEDIUM 5.3 The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin fo… wordfence
d0064a76-3ccc-4dd6-b312-d19abb3944fa
< 3.4.5
MEDIUM 5.3 The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to unauthorized access… wordfence
CVE-2026-2126 MEDIUM 5.3 The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incor… nvd
CVE-2026-1980 MEDIUM 5.3 The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on … nvd
CVE-2026-1657 MEDIUM 5.3 The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including… nvd
CVE-2026-1656 MEDIUM 5.3 The Business Directory Plugin for WordPress is vulnerable to authorization bypass due to a missing authorization check i… nvd
CVE-2026-1558 MEDIUM 5.3 The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, … nvd
CVE-2026-1336 MEDIUM 5.3 The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and m… nvd
CVE-2026-1305 MEDIUM 5.3 The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and inclu… nvd
CVE-2025-14357 MEDIUM 5.3 The Mega Store Woocommerce theme for WordPress is vulnerable to unauthorized modification of data due to a missing capab… nvd
CVE-2025-14294 MEDIUM 5.3 The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… nvd
CVE-2025-13864 MEDIUM 5.3 The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up… nvd
CVE-2025-13842
< 7.5.1
MEDIUM 5.3 The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions … nvd
CVE-2025-13113 MEDIUM 5.3 The Web Accessibility by accessiBe plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions … nvd
← Prev 1124 1125 1126 1127 1128 1129 1130 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top