πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1143 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b4f32ec5-c744-45ca-a7a2-3d4a241f82c1 MEDIUM 5.3 The Snow Effect plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
b4d9acfb-bb9d-4b00-b439-c7ccea751f8d
< 3.22.2
MEDIUM 5.3 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Expo… wordfence
b4ce6cb2-a02a-4b4c-8887-22ee6115509f
< 3.5.7
MEDIUM 5.3 In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible … wordfence
b4cb5ec6-34f5-419d-a1eb-3a75dd63cb60 MEDIUM 5.3 The WooCommerce Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and… wordfence
b4a88c2f-12d2-46c5-a14a-dfec6382a81b MEDIUM 5.3 The Import YouTube videos as WP Posts plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
b49ce4a2-52ad-4824-86fc-5edd2e33802d
< 1.1.28
MEDIUM 5.3 The Hydra Booking β€” Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment ve… wordfence
b49978c1-9254-4229-8d32-e12896301f3d
< 2.6
MEDIUM 5.3 The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a mi… wordfence
b4956173-b306-401c-b966-df884e8979e0
< 4.0.19
MEDIUM 5.3 The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page l… wordfence
b48e5973-6923-47cc-a660-ecc989f540f8
< 14.1.0
MEDIUM 5.3 The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 14… wordfence
b48b9170-4dd9-4004-a081-488cafbc7597
< 3.3.27
MEDIUM 5.3 The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure … wordfence
b4570948-1625-44b3-8af6-73765d9710ee
< 3.11
MEDIUM 5.3 The WordPress Email Marketing Plugin – WP Email Capture plugin for WordPress is vulnerable to Sensitive Information Ex… wordfence
b4363600-666a-4a75-a817-4af679ab400c
< 5.9.3
MEDIUM 5.3 The ARMember Premium plugin for WordPress is vulnerable to unauthorized access of data, modification of data, or loss of… wordfence
b424f25d-66c7-4c1b-9712-7b857806f7e4
< 2.8.4
MEDIUM 5.3 The Password Protected plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and inclu… wordfence
b3e03668-c9ee-4c4b-8240-998ef45a5326
< 3.1.3
MEDIUM 5.3 The WP STAGING WordPress Backup Plugin Free and Pro plugin for WordPress is vulnerable to Sensitive Information Exposure… wordfence
b3cc3835-25f5-43b3-82be-397b8b3bd369
< 1.53.2
MEDIUM 5.3 The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… wordfence
b3c6ba21-7631-4bbd-b08e-926d2f129cc3
< 7.7
MEDIUM 5.3 The SEOPress – On-site SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,… wordfence
b3c17ba3-4fc8-439c-8ce3-bd95d7ed2474
< 2.1
MEDIUM 5.3 The coreActivity: Activity Logging plugin for WordPress plugin for WordPress is vulnerable to IP Address Spoofing in all… wordfence
b3c15924-d430-48e3-9804-fa83605b9c24
< 2.0.1
MEDIUM 5.3 The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability… wordfence
b3940953-fdd4-4759-8476-a421cfbbbd30
< 1.1.1
MEDIUM 5.3 The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to unauthorized access du… wordfence
b3325317-4ce7-468d-aee7-9b40fdf61d3c
< 6.0.3.4
MEDIUM 5.3 The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜page’ para… wordfence
b311b404-f808-40fc-9f09-4eac05bce798 MEDIUM 5.3 The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1… wordfence
b30ac1b0-eae2-4194-bf8e-ae73b4236965
< 7.6.4
MEDIUM 5.3 The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec… wordfence
b308c032-14a1-42f7-866c-adacc7d9402e MEDIUM 5.3 The JobHunt Job Alerts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
b3075193-41ae-4e3d-acf7-b94105b67456 MEDIUM 5.3 The Allada T-shirt Designer for Woocommerce – Custom Product Designer for T-shirt personalization and design plugin fo… wordfence
b2fc119c-6545-48a5-aa27-852edce50b39
< 2.2.1
MEDIUM 5.3 The VW Education Lite theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
← Prev 1140 1141 1142 1143 1144 1145 1146 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top