πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1128 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2025-12074 MEDIUM 5.3 The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 v… nvd
cfeca343-c796-45d5-a71d-8211d8b38b3e MEDIUM 5.3 The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to … wordfence
cfec1129-a017-453e-8a4e-ed31dee2bb30
< 4.0.8.6
MEDIUM 5.3 The LoginWP - Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
cfe45a6b-bd31-4716-9d4d-f7d1b48f9884
< 1.9.0
MEDIUM 5.3 The Intranet & Private Site – All-In-One Intranet plugin for WordPress is vulnerable to unauthorized access due to a m… wordfence
cfbc90b9-af91-49ac-ad3d-a37c17e8ba6d MEDIUM 5.3 The 1003 Mortgage Application plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and incl… wordfence
cfb63a23-71f1-4497-a1ba-5b10abf0e22a
< 3.9.6
MEDIUM 5.3 The WooCommerce Product Table Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
cfa6bc4b-7fc8-40c7-bfca-18410f6cd615
< 5.2.2
MEDIUM 5.3 The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom… wordfence
cf8919d4-6ca7-44ed-ae2a-14b0c96a568f
< 2.1.0
MEDIUM 5.3 The Maintenance Redirect plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including,… wordfence
cf72cc4c-ec99-46c2-bb12-d11e9d51ffc8
< 3.1.36
MEDIUM 5.3 The Icegram Engage – Popups, Optins, CTAs & lot more… plugin for WordPress is vulnerable to unauthorized access due … wordfence
cf69a071-d4dd-4ed7-8366-cdd205724a9b MEDIUM 5.3 The BookPro - Appointment Booking WordPress Plugin plugin for WordPress is vulnerable to Insecure Direct Object Referenc… wordfence
cf6563a4-56ca-46b1-a854-aad7cc550f73
< 1.4
MEDIUM 5.3 Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic … wordfence
cf49d3fb-de14-42bc-bf51-f9adceba0d32
< 1.5.1
MEDIUM 5.3 The Xpro Addons β€” 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data d… wordfence
cf2b5d05-24a3-4bc8-9dde-a7e8ce13ea16
< 3.6.2
MEDIUM 5.3 The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to … wordfence
ceef1c0b-c845-4c03-8763-89a1823f69fb
< 1.16.0
MEDIUM 5.3 The Wikipedia Preview plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
cedf6dea-c2d8-4cbd-8a38-3b903e722668 MEDIUM 5.3 The Monetag Official Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
cedf147d-82ba-41f2-b30a-1befedf8694a
< 1.1.18
MEDIUM 5.3 The Addonify – Compare Products For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
cededc46-ebf5-4614-b9d7-2047f70635f7
< 4.1.10
MEDIUM 5.3 The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to unaut… wordfence
ced798e1-b002-4a47-a820-8062e287d8da MEDIUM 5.3 The JobBoard Job listing plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
ceb7d0a7-ea34-4c6f-a144-660debc74a9e
< 1.1.5
MEDIUM 5.3 The Advance Product Search plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … wordfence
ce8fa964-d543-4d46-a534-e403dff4f425
< 5.11
MEDIUM 5.3 The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure D… wordfence
ce80267b-3c62-4105-a069-ba7497dacd07
< 3.7.2
MEDIUM 5.3 The CitiLights theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
ce546f2e-5323-44b9-b980-5619f2db2944 MEDIUM 5.3 The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
ce457c98-c55b-4b71-a80b-393eceb9effd
< 2.7.31
MEDIUM 5.3 The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 v… wordfence
ce33f2a6-43a4-4382-97ff-9588e92b483d
< 1.4.6
MEDIUM 5.3 The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference in al… wordfence
ce297421-506c-4230-837e-96200677e1e2
< 4.1.0
MEDIUM 5.3 The Survey Maker – Best WordPress Survey Plugin plugin for WordPress is vulnerable to IP Address Spoofing in all versi… wordfence
← Prev 1125 1126 1127 1128 1129 1130 1131 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top