πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1129 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ce101aad-10a3-4a8c-9f4a-0e38e35b4dab
< 2.0.8
MEDIUM 5.3 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralizat… wordfence
cdc37da4-9de6-467b-a168-e3fa29baa06b
< 1.7.1037
MEDIUM 5.3 The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthor… wordfence
cdb9c321-1a2c-4593-9947-2071a908ee1c MEDIUM 5.3 The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and in… wordfence
cdb7a2b8-bfc8-4f3f-bd61-744d015358f8
< 1.2.1
MEDIUM 5.3 The Gallery for Google Photos plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, an… wordfence
cda2465e-b17e-4b5c-ad86-3c3c7a354d03
< 3.6.8
MEDIUM 5.3 The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sens… wordfence
cd93b123-bcab-41a2-910c-8d15e726297b
< 3.6.1.3
MEDIUM 5.3 The JetSearch plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.6… wordfence
cd6dcfe2-91c4-42c1-ada4-91c6f25c4690
< 3.21.0
MEDIUM 5.3 The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t… wordfence
cd5f5861-5be4-456d-915d-bafb7bff2110
< 2.11.2
MEDIUM 5.3 The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPr… wordfence
cd2dcc09-7de5-489a-95a5-e82cb88d8cbb
< 2.5.97
MEDIUM 5.3 WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information. wordfence
cd177a43-6059-4125-9408-1090b9a54117 MEDIUM 5.3 The Security, Antivirus, Firewall – S.A.F plugin for WordPress is vulnerable to IP Address Spoofing in versions up to,… wordfence
cd03483a-f46c-4e17-8b58-df87b0ad7fa3
< 1.0.4
MEDIUM 5.3 The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on th… wordfence
cce13008-a0f8-458f-ade5-450d0dcc966a
< 3.6.3
MEDIUM 5.3 The Social Share Icons & Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data du… wordfence
ccdf9626-e1c2-404d-90b0-5edbfeba2faf MEDIUM 5.3 The Ship Per Product plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
ccbf81d8-ecae-4e00-9a26-aea0976aa1f1
< 4.0.0
MEDIUM 5.3 The Education Base theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
ccbeb69e-6476-42a6-86ac-723947c70301
< 2.4.61
MEDIUM 5.3 The BuddyBoss Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
ccb65de5-bfb5-47db-87c9-ad46e65924b8 MEDIUM 5.3 The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi… wordfence
ccaccf03-4162-4365-9f12-0363a78e91d4
< 2.19.18
MEDIUM 5.3 The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information … wordfence
cc8147ae-fb6c-444c-9113-98bdeff3a4dd
< 1.2.2
MEDIUM 5.3 The Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab plugin for WordPress is vulnerable to unauthorized … wordfence
cc6edf0a-7917-4ec1-afc0-a1000955cf2e
< 2.7.4.2
MEDIUM 5.3 The JetElements plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
cc69c2ff-5936-4b5d-b476-badca08eeeac
< 1.3.7
MEDIUM 5.3 The Themebeez Toolkit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
cc472230-bd80-4bdb-a969-fed7551cc60d
< 3.4.1
MEDIUM 5.3 includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure. wordfence
cc3d49c5-3054-4e1f-b571-6591a0b31d69
< 2.0.3.1
MEDIUM 5.3 The Everest Forms plugin for WordPress is vulnerable to unauthorized form submission due to a missing validation check i… wordfence
cc365364-4185-4dcb-a3b6-36c9781b0916
< 2.0.0.7
MEDIUM 5.3 The ThemeGrill Demo Importer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
cc3619da-815b-48ec-83b1-b7c15f729304
< 5.8.0
MEDIUM 5.3 The wProject theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
cc2cd74d-b828-4524-b33d-c806bfd970b9
< 1.13.9
MEDIUM 5.3 The Email Marketing for WooCommerce by Omnisend plugin for WordPress is vulnerable to Sensitive Information Exposure in … wordfence
← Prev 1126 1127 1128 1129 1130 1131 1132 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top