πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1140 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
babf88c4-6328-4ba2-97e4-e1eaaa549dbb
< 2.8.16
MEDIUM 5.3 The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and… wordfence
baa16b34-760f-4033-a9ee-e14b35e79542
< 5.2.4
MEDIUM 5.3 The MotoPress Hotel Booking plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inclu… wordfence
ba9b2d34-c1a3-47c2-9eee-51592faa8805
< 4.2.24
MEDIUM 5.3 The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized ac… wordfence
ba88964e-7487-4cd5-ab3e-bd33d14a61df
< 3.8.3
MEDIUM 5.3 The Simple Social Media Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio… wordfence
ba886cec-7c0c-40dd-a6eb-bc770d571974 MEDIUM 5.3 The leadlovers forms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
ba6f8837-813c-4e16-9adb-fdc90ccaf0ca MEDIUM 5.3 The Content Audit Exporter plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… wordfence
ba670636-4b83-4915-969e-f02b9786b7d5
< 1.01.6
MEDIUM 5.3 The Builder for WooCommerce reviews shortcodes – ReviewShort plugin for WordPress is vulnerable to unauthorized access… wordfence
ba465ba0-70c2-4b34-9b55-96725e3ce5a4 MEDIUM 5.3 The WP SendFox plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… wordfence
ba2623b6-69b4-4596-a1af-cf37083706e8
< 2.0.5
MEDIUM 5.3 The Addonify plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
ba027271-b7f9-4bdb-a62b-801fd07f28fd MEDIUM 5.3 The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and… wordfence
b9f627f0-779c-4d57-a471-ce742e3a5dd5
< 4.20.9
MEDIUM 5.3 The Leaky Paywall plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 4.20.8.… wordfence
b9f2be74-fedd-4844-95a4-a84318489e58
< 2.2.4
MEDIUM 5.3 The Payment Gateway Pix For GiveWP plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
b9e844c1-38c1-4b3c-98a4-71d87ca6293b MEDIUM 5.3 WordPress Portable phpMyAdmin Plugin 1.4.1 and below has Multiple Security Bypass Vulnerabilities including /pma/phpinfo… wordfence
b9d288b8-a0de-493b-b677-3f9bf8211504
< 2.0
MEDIUM 5.3 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access du… wordfence
b9cf99e9-47fa-4ca0-8f6c-4b0e75d44008
< 0.8.4
MEDIUM 5.3 The Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content plugin for WordPress … wordfence
b9b21f8e-8d66-4d3e-a383-bea20a3c4498
< 2.6.1
MEDIUM 5.3 The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions … wordfence
b9961347-7c47-4fa1-af35-609c39a6cd8b
< 1.3.3
MEDIUM 5.3 The WPZOOM Addons for Elementor – Starter Templates & Widgets plugin for WordPress is vulnerable to unauthorized acces… wordfence
b990915d-219b-4329-b7a8-e0c13cad7530
< 10.1.0
MEDIUM 5.3 The SmartMag theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and excluding, 1… wordfence
b9852f61-6502-4e27-9de4-ff1a79accd71
< 2.1.10
MEDIUM 5.3 The Download After Email plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
b94202ef-75d6-4b6f-96b5-f9760cc0a628
< 3.0.4
MEDIUM 5.3 The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve t… wordfence
b93f8036-4a89-45e6-b86f-9d57e1662a35 MEDIUM 5.3 The Fantastic Content Protector Free plugin for WordPress is vulnerable to unauthorized plugin settings reset due to a m… wordfence
b92913fa-aa1e-40a0-9a48-d730b2102217
< 2025.0
MEDIUM 5.3 The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_… wordfence
b917c16f-cd0b-400a-b0e8-48ae32d18339
< 270.5
MEDIUM 5.3 The ConveyThis plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
b9047775-2d72-4eb5-9339-419f95aa19b2
< 2.0.0
MEDIUM 5.3 The Acme Fix Images plugin for WordPress is vulnerable to unauthorized access to the acme_fix_images_ajax_callback funct… wordfence
b8f82dad-cba6-484e-8e30-6370ec2ba2d8
< 2.1.2
MEDIUM 5.3 The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
← Prev 1137 1138 1139 1140 1141 1142 1143 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top