πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1137 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bf2b8b9e-755f-4b24-99c8-0d221c9c19a7
< 3.0.0
MEDIUM 5.3 The Membership For WooCommerce – WordPress Membership Plugin, Restrict Content, Build Online Communities, Paywall & Co… wordfence
bf22affe-13b9-4f88-aaff-24eaa8df7e5d
< 1.3.13
MEDIUM 5.3 The User Registration Stripe plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
befc6373-1833-4e5b-9500-19fbc3aa110e MEDIUM 5.3 The Coming Soon Page – Responsive Coming Soon & Maintenance Mode plugin for WordPress is vulnerable to Sensitive Infor… wordfence
befc1787-7617-410a-b897-7089c2d9b413
< 1.1.31
MEDIUM 5.3 The Tablesome plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
bef84287-cbff-41c8-8cf8-3e0e12b0311b
< 2.0.9
MEDIUM 5.3 The Miraculous - Multi Vendor Online Music Store Elementor WordPress Theme theme for WordPress is vulnerable to unauthor… wordfence
bee2e520-46cc-4b54-9849-fafb9b37ba19
< 5.0.0
MEDIUM 5.3 The WP ULike plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including… wordfence
beb8ea66-3cd7-452f-9e64-8439de0ddc55
< 2.21.0
MEDIUM 5.3 The Quform - WordPress Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions… wordfence
beae9073-5293-4a89-8c9a-8c5276891684
< 4.19.0
MEDIUM 5.3 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized acce… wordfence
be9522c8-3561-48fe-89ef-62e0fcb085b0
< 4.7.9
MEDIUM 5.3 The ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7.8. Th… wordfence
be826d7f-6f8e-4942-81d5-2b00debd56fc
< 9.5.10.1
MEDIUM 5.3 The Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) plugin for WordPress is vulne… wordfence
be6db702-43bc-4d1f-a222-d323c70c6bb3
< 1.7.1053
MEDIUM 5.3 The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthor… wordfence
be5cc744-e88e-4a8b-81d1-3e05abba19d8
< 1.0.47
MEDIUM 5.3 The Checkout for PayPal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
be4fac77-93f3-4c5d-b139-66e799143533 MEDIUM 5.3 The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
be3411ec-0e34-4b0b-a04c-98ac94396989
< 2.7.1
MEDIUM 5.3 The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due t… wordfence
be33065e-dae8-44cf-9f8a-f9971f2743ff
< 3.9.9
MEDIUM 5.3 The EmbedPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the handle… wordfence
be23d61f-1e7f-40fb-88ca-dd0ed226a7c5
< 2.15.0
MEDIUM 5.3 The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to In… wordfence
be07fa12-7c2a-48f6-9792-17d8b2f5d209 MEDIUM 5.3 The Viral Loops WP Integration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t… wordfence
be01ffb6-9ef0-41a1-870c-fbeee48d886f
< 3.3.1
MEDIUM 5.3 The WPC Order Tip for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to… wordfence
bdeb5494-3239-417c-86dc-488e35f1b7f9
< 13.7.1
MEDIUM 5.3 The Indeed Membership Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
bdde4399-af90-4528-92a4-5176dfa5e453 MEDIUM 5.3 The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa… wordfence
bdd1bb49-5a0f-434c-bb05-03c4a548dec1 MEDIUM 5.3 The ShipDepot for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
bdc84664-2a04-4cc6-ac3f-48bfd432691f
< 4.7.27
MEDIUM 5.3 WordPress Core is vulnerable to Denial of Service via Cache Poisoning in versions between 4.7.0 and 6.3.1. In cases wher… wordfence
bdbd3a1a-a206-4e50-893d-1b2d6c8d153a
< 3.0.6
MEDIUM 5.3 The Visual Form Builder WordPress plugin before 3.0.6 is vulnerable to CSV injection allowing a user with low level or n… wordfence
bdaa32cd-a148-4554-9fd5-f5b0a5b2d1c3
< 5.5.1
MEDIUM 5.3 The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthe… wordfence
bd9336ba-0a91-4fe5-b564-1adf739f4193
< 4.7.2
MEDIUM 5.3 The Simple Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
← Prev 1134 1135 1136 1137 1138 1139 1140 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top