πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1141 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b8ef40bf-e33f-4e62-8ad6-724657138d4b MEDIUM 5.3 The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
b8be3b6e-a035-4e6f-ba2b-ce9e59ebf2e0
< 6.29
MEDIUM 5.3 The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all ve… wordfence
b8b07ce8-d6ee-4ede-8394-4aae24c610b2
< 1.9.9.2
MEDIUM 5.3 The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress i… wordfence
b8ae2ede-4288-48ef-9fc9-09ef80363a3b
< 2.5.3
MEDIUM 5.3 The Direct Payments for WooCommerce – Bank Transfer, Mobile Money, Crypto and Peer-to-Peer (P2P) Payments plugin for W… wordfence
b8aa8208-e897-4c08-9253-76bbe159bee8
< 6.60.29
MEDIUM 5.3 The Compress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
b8a2bbfe-eb87-4e26-ba20-bc406d681124
< 1.10.8
MEDIUM 5.3 The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and inclu… wordfence
b88787ca-314d-4750-897b-8bf3f5374c5c
< 4.3.8
MEDIUM 5.3 The ECS plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 4.3.7. This is due t… wordfence
b884cb04-feab-4579-9a38-6d5654525372
< 7.6.1
MEDIUM 5.3 The Ajax Load More – Infinite Scroll plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi… wordfence
b85fc103-20e5-4599-8ed5-5bd5d9c447ee
< 7.0.3
MEDIUM 5.3 The Eyewear prescription form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inc… wordfence
b853d615-e62f-4365-9f07-bfba60b3a030
< 4.0.1
MEDIUM 5.3 The DHL for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and incl… wordfence
b84ae3e0-de4f-41d6-8944-fadaf6fdcf79
< 3.8.2
MEDIUM 5.3 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure … wordfence
b8415e5f-17a4-425c-ac28-5dd886d1bcf1
< 3.6.10
MEDIUM 5.3 The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions … wordfence
b83e3fdc-6d16-48c5-8773-f2d053944584
< 2.8.50
MEDIUM 5.3 The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Sensitive Infor… wordfence
b82a9ae8-ff82-40bf-a5d4-5175daab9146
< 1.1.5
MEDIUM 5.3 The Instant CSS plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capabi… wordfence
b8261317-462b-49c5-9526-20b695895e49
< 2.1.8
MEDIUM 5.3 The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Sensitive Information Exp… wordfence
b813f3d8-b765-4cf5-aec0-786140e2a0ce
< 2.3.0
MEDIUM 5.3 The WP Ultimate Review plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and… wordfence
b7f52e71-da35-4b46-b658-d293f81b5dc9
< 2.1.3
MEDIUM 5.3 The Events Addon for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing ca… wordfence
b7e7222e-93ea-42d5-9749-deb6b1d920af MEDIUM 5.3 The Booknetic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
b788e59a-4796-4ad9-8098-01b84908f97c
< 2.0.4
MEDIUM 5.3 The Push notification for Mobile and Web app plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
b786ad61-eed7-4be7-9204-f440570916ea
< 7.0.7
MEDIUM 5.3 The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
b77c4471-57a2-4655-9ff5-41057702f381
< 2.0.0
MEDIUM 5.3 The Forumax – Advanced Community Forum Plugin plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
b7413f09-14d5-4cb6-9bcd-c36a14a13e88
< 3.1
MEDIUM 5.3 The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in … wordfence
b73364ea-acec-49d1-bb43-9c3b90ac281b
< 4.0.1
MEDIUM 5.3 The DHL for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and in… wordfence
b6f54ca4-297f-44e8-8bb3-25cdc52f94ff MEDIUM 5.3 The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, a… wordfence
b6d8ea0b-3c54-4d9d-8f14-2055510f3119
< 1.5.4
MEDIUM 5.3 The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions … wordfence
← Prev 1138 1139 1140 1141 1142 1143 1144 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top