πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1144 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b2f9203f-15c7-4179-86ef-44b0e2788b3c MEDIUM 5.3 The WP Virtual Assistant plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
b2c7fb39-d128-4285-8bc3-1e192e1e1196
< 1.1.10
MEDIUM 5.3 The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error … wordfence
b29dbd24-6c63-46d8-b245-7194cab17624
< 1.7.6
MEDIUM 5.3 The SiteGround Email Marketing plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
b29144f7-08cb-4703-a977-4fece763abbd
< 6.0.4
MEDIUM 5.3 The Democracy Poll plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
b28e313a-3527-468f-8e86-6e51962af950 MEDIUM 5.3 The Altair theme for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.2.2. This is… wordfence
b23dec43-ad7d-45d9-910e-b024b3c750c9
< 7.0.0
MEDIUM 5.3 The Post My CF7 Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
b23de3eb-ae2a-4165-9251-7a135bc34b73
< 6.4.14
MEDIUM 5.3 The Advanced Booking & Appointment System – Webba Booking Calendar plugin for WordPress is vulnerable to unauthorized … wordfence
b23bdba3-8947-47e4-b208-55e42865ab72
< 2.17.6
MEDIUM 5.3 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… wordfence
b23afc11-c31d-4569-8f4b-8141eef7b3d9
< 4.1.1
MEDIUM 5.3 The Custom Login plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unkno… wordfence
b1dea93c-437b-45ac-9dc3-07d3aa3f1c9f
< 4.0.3
MEDIUM 5.3 The Peach Payments Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
b1dd3845-a88d-41aa-acf4-66fd1a6819ff
< 3.0
MEDIUM 5.3 The Captcha Code plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.9. This makes … wordfence
b1be4b6c-ce48-49a2-8d2c-89c9611c8750
< 1.3.14.0
MEDIUM 5.3 The Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensit… wordfence
b192dd62-477d-463d-a284-9f3232db27ca
< 7.5.2
MEDIUM 5.3 The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Sensitive Information Exposure in all v… wordfence
b1892207-0e51-4b2e-bc71-d6a0111b7041
< 7.8.1
MEDIUM 5.3 The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8… wordfence
b1800f37-f9ab-454b-84f7-4d5eb5ed3acf MEDIUM 5.3 The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, a… wordfence
b1715959-532a-4dd7-b384-0bd5f2673e2b
< 10.30.34
MEDIUM 5.3 The Salon Booking System – Free Version plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
b15d1992-ecf9-4253-b832-056b34f42b48
< 1.2.8
MEDIUM 5.3 The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions… wordfence
b14acbc6-a6af-43f0-8371-c85e5abcf8eb MEDIUM 5.3 The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized access due t… wordfence
b1469b02-c52d-4a02-a974-81dd1e2c1f97
< 1.9.9.1
MEDIUM 5.3 The WPLMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in a… wordfence
b1446daf-662d-479c-8fc5-80b27b04d6c4
< 2.0.7
MEDIUM 5.3 WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type… wordfence
b11b886e-72a7-4b27-a4ac-f4586c3ef722
< 3.6.2
MEDIUM 5.3 The Order Listener for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
b102af8f-2bc3-4548-9a90-d1280b058173 MEDIUM 5.3 The Post Thumbnail Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… wordfence
b0e1546b-c8cc-4d57-9909-153209e3a9c6
< 3.0.1
MEDIUM 5.3 The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to… wordfence
b0d4c009-d969-49bb-a56b-a704e5f89a86
< 2.1.1
MEDIUM 5.3 The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and includin… wordfence
b0c80f18-5319-436d-b989-e6f5e6ab58ea
< 2.0.1
MEDIUM 5.3 The Anti Spam and list cleaner – AcyChecker plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
← Prev 1141 1142 1143 1144 1145 1146 1147 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top