πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1136 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c16c8f50-4fb6-4fe6-aa35-ad5105dee8d9 MEDIUM 5.3 The Wp EMember plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, v1… wordfence
c1558b08-a33b-4cf2-bacb-c88065f513cc
< 4.5.6
MEDIUM 5.3 The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… wordfence
c12cca1e-2d6a-4946-bff7-bb71e570e9d5
< 2.0.7
MEDIUM 5.3 The CatFolders Document Gallery & PDF Library plugin for WordPress is vulnerable to unauthorized access in all versions … wordfence
c1033b4d-82a0-4484-aebf-f35d6a2a9a13
< 3.8.0
MEDIUM 5.3 The EmbedPress plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on t… wordfence
c0d1145d-f888-4217-963c-c058a6a56f74
< 3.6.8
MEDIUM 5.3 The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to unau… wordfence
c0c60ee5-65e4-45a7-a4b5-53de7dd6a65b
< 1.6.1
MEDIUM 5.3 The UPI QR Code Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
c0bba475-b498-4c2d-a3f2-f4766a2b8616
< 3.5.2
MEDIUM 5.3 wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause… wordfence
c0a42af0-72da-49f3-a2c5-e76a9e918446
< 4.9.9
MEDIUM 5.3 The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin … wordfence
c09318f1-04b2-44e5-a184-c07942ae5778
< 3.2.2
MEDIUM 5.3 The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & … wordfence
c092629f-177c-4201-9fdd-defe47f85811 MEDIUM 5.3 The Post From Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
c08444ef-77bc-4e9d-8d94-04b90cc99ded
< 3.5.4
MEDIUM 5.3 The JetFormBuilder β€” Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of da… wordfence
c034d2a2-20c4-4c32-8cfe-b80a62bdfdeb
< 1.7.1
MEDIUM 5.3 The ShareYourCart plugin before 1.7.1 for WordPress allows remote attackers to obtain the installation path via unspecif… wordfence
c023b91e-f633-41a6-b2d7-bcb3f1d026b7
< 2.1.1
MEDIUM 5.3 The Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all versions up to, and including… wordfence
c01a8fbc-c16a-40e2-b628-f874cd3b21e4
< 1.3.3
MEDIUM 5.3 The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Sensitive Information Exposure in all … wordfence
c0163382-9b53-4c74-b9bd-c3baa14faee1 MEDIUM 5.3 The EventON (Pro) - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized access du… wordfence
bfef0be2-b73d-43f9-a3bc-f61846fa0704 MEDIUM 5.3 The Xendit Payment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
bfe48948-7fc9-4806-b1b5-9fac5a6c7d96
< 1.68.5
MEDIUM 5.3 Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests… wordfence
bfcbd6fb-f599-4a85-aabb-d03d2716ba00 MEDIUM 5.3 The YT Player – Embed and Customize Video Players plugin for WordPress is vulnerable to unauthorized access due to a m… wordfence
bfba1c2c-6679-4c6c-95fd-bae391e6aa0b
< 1.2
MEDIUM 5.3 The WpXmas-Snow plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
bfb473a6-08ba-4b23-877d-4aa661c0053f
< 2.3.28
MEDIUM 5.3 The Contact Form builder with drag & drop - Kali Forms plugin for WordPress is vulnerable to unauthorized modification o… wordfence
bfa9a9f6-dfbb-442c-af2c-af3d44e7b0f1
< 1.1.1
MEDIUM 5.3 The TrustedLogin Vendor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions prior to 1.… wordfence
bf8aa169-df51-46db-8c65-f1543d4f75f9
< 2.7.7
MEDIUM 5.3 The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6.… wordfence
bf79cc31-5dd4-4b4f-9c5d-5adaea7689a5
< 1.26.9
MEDIUM 5.3 The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… wordfence
bf5dab26-6674-49d9-bc14-13430f4d644f
< 5.5.8
MEDIUM 5.3 The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to unauthorized ac… wordfence
bf4eca37-066f-428c-a4f7-061ce06e1142
< 4.2.20
MEDIUM 5.3 The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build the Next Amazon, eB… wordfence
← Prev 1133 1134 1135 1136 1137 1138 1139 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top