πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1138 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bd7c442f-5c91-4c52-933a-8a6fb7adca8c
< 2.5.9
MEDIUM 5.3 The Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.5.8 … wordfence
bd7bf797-fa51-444b-9252-f004e9116fd5 MEDIUM 5.3 The PixProof – Easy Photo Proofing for Photographers plugin for WordPress is vulnerable to unauthorized access due to … wordfence
bd67a8e7-6ccc-4c76-9baa-f5dac225d789 MEDIUM 5.3 The DesignThemes Directory Addon plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
bd46352a-5428-467d-9456-772ef816efb1 MEDIUM 5.3 The Universal Google Adsense and Ads manager plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
bd2f0997-8373-4304-ad60-3a98f48ec530
< 3.2.11
MEDIUM 5.3 The Hestia theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in a… wordfence
bd2ea430-48ce-43c3-ba3d-8ef5f91460ce
< 1.3.5
MEDIUM 5.3 The Newsmatic theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, … wordfence
bd1f12ac-86ac-4be9-9575-98381c3b4291 MEDIUM 5.3 The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenti… wordfence
bd1cc121-65c2-4e6f-8b07-91fe75bca9db
< 1.6.19
MEDIUM 5.3 The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to unauthorized access d… wordfence
bd0ac7bf-e786-47b8-ab3b-ca59cdb3c19e
< 1.5.6
MEDIUM 5.3 The Travel Agency theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
bcf7af0d-6df8-4f90-a244-f942f678434f
< 2.5.0
MEDIUM 5.3 The PDF Poster – Display PDF Files with Custom Viewer plugin for WordPress is vulnerable to unauthorized access due to… wordfence
bce8dc07-e790-481d-8b4f-9d61d3b6b941
< 4.22.10
MEDIUM 5.3 The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
bccdff52-e20c-49d5-9d82-ae7a16133793
< 1.3.9
MEDIUM 5.3 The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to Sensitive Infor… wordfence
bcc6a4a5-b133-4ee1-a345-a7c812624b03 MEDIUM 5.3 The 2Checkout Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data du… wordfence
bcc1f2bf-4dd6-42cd-af05-52b73654aca2 MEDIUM 5.3 The Pure WC Variation Swatches plugin for WordPress is vulnerable to unauthorized [access of data|modification of data|l… wordfence
bcc10e91-4810-4a0d-919c-de3e87137f76 MEDIUM 5.3 The Page Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
bcac3b4e-b80f-4201-9e56-8990013c4ab9 MEDIUM 5.3 An issue was discovered in the ajax-bootmodal-login plugin 1.4.3 for WordPress. The register form, login form, and passw… wordfence
bca41dd8-5bd3-4fee-9f3f-feb8f1a4c687
< 1.33.4
MEDIUM 5.3 The IP2Location Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabilit… wordfence
bca1664e-5911-4c06-8ae2-1830b0c376fa
< 16.9
MEDIUM 5.3 The WordPress User Extra Fields plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
bc9e728a-5aae-487c-bd17-e78141084f10
< 2.1.15
MEDIUM 5.3 The Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar plugin for WordPress… wordfence
bc82745a-f1d3-48fc-ba7b-3ff726edae34
< 2.1.1
MEDIUM 5.3 The Bricksforge plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
bc611a4b-f3eb-48ed-8904-27124775ed29
< 0.4.15
MEDIUM 5.3 The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
bc524e3e-9b7c-47ae-ab44-c327b287b81a
< 6.7.0.81
MEDIUM 5.3 The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… wordfence
bc509aa6-b2e3-4589-8a26-a494c4be31f4 MEDIUM 5.3 The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
bc442f79-f682-4311-89fd-f447da1a2ab8
< 3.14.0
MEDIUM 5.3 The Seriously Simple Podcasting plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up … wordfence
bc3b2645-7b57-4884-99c5-e37dbd4a9600
< 1.8.10
MEDIUM 5.3 The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is… wordfence
← Prev 1135 1136 1137 1138 1139 1140 1141 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top