ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1145 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b0a9f3d2-aa7f-4fc2-9cfd-b69ec3f63160 MEDIUM 5.3 The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability … wordfence
b083cf9d-bcfe-4234-a816-2d216da28b57
< 1.13.2
MEDIUM 5.3 The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and includi… wordfence
b078e446-61e7-4ce1-b9a9-480ccc388c72
< 2.1.7
MEDIUM 5.3 The Perfmatters plugin for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing… wordfence
b061facb-0411-4b81-adbd-b1419b7210df
< 6.8.2
MEDIUM 5.3 The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
b05b0f6d-ffa4-40f4-b969-1153192c52d6
< 2.3.2
MEDIUM 5.3 The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versio… wordfence
b04a7ef8-13bb-455e-8ca8-22f3eec15bcb
< 5.0.6
MEDIUM 5.3 The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to Sensi… wordfence
b030aa28-5310-4f69-8b86-7e0b0bae741b
< 8.2.7
MEDIUM 5.3 The WoodMart theme for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 8.2.6.… wordfence
b024f6ce-c3ec-4ed9-a8ea-54f926e38443
< 1.6
MEDIUM 5.3 The WooCommerce Email Test for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.5 … wordfence
affe1bab-e534-4c79-a057-6b1268437575
< 1.2.22
MEDIUM 5.3 The Ziina plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in a… wordfence
afefe8fd-0078-4fd8-bdae-03e60fc33e87 MEDIUM 5.3 The AnalyticsWP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… wordfence
afec4c8c-a18d-4907-8879-2412f8a1abed
< 5.4.0
MEDIUM 5.3 The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin… wordfence
afe275b4-edc0-4b19-a91f-5099a085e8ce
< 5.0.4
MEDIUM 5.3 The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ver… wordfence
afc9114b-80b7-4caf-ab6b-35747ff5057b
< 1.1.1
MEDIUM 5.3 The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to Sensitive Data Exposure… wordfence
afc3531d-6134-4b45-b532-37430d96a8fb
< 2.0.0
MEDIUM 5.3 The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… wordfence
afbcee72-fe0c-4288-bcf7-e2eaea8029d6
< 5.6.5
MEDIUM 5.3 The Eduma theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in al… wordfence
af97a8aa-f42b-46c8-b79b-d1c3220fdf58
< 3.19.10
MEDIUM 5.3 The 12 Step Meeting List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… wordfence
af955f69-b18c-446e-b05e-6a57a5f16dfa
< 4.1.8
MEDIUM 5.3 The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, a… wordfence
af870e80-ad9e-4f45-952f-9ffb07ceca9c
< 1.4.4
MEDIUM 5.3 The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… wordfence
af803612-96ae-41ee-8ad3-8f9319b147e8
< 2.3.6
MEDIUM 5.3 The Button Generator – easily Button Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… wordfence
af54654b-60af-446d-b170-ee0a1ebed22c
< 2.9.7.1
MEDIUM 5.3 The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vul… wordfence
af40f0e4-96cf-4eac-842b-6df6279cab44
< 3.2.9
MEDIUM 5.3 The New User Approve plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.2… wordfence
af3105ed-d383-4ce6-9317-5762f97b14e3 MEDIUM 5.3 The Client Dash plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
af2645cc-aa96-45b4-8f22-16d02224cb3b MEDIUM 5.3 The Scientific and Interactive Blocks – inseri core plugin for WordPress is vulnerable to unauthorized access due to a… wordfence
af138d3c-9f43-4346-bcb5-cb408f10b253
< 4.7.16
MEDIUM 5.3 The MasterStudy LMS Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… wordfence
af01cba6-40df-4eb9-beec-4716909a671b
< 1.4.8
MEDIUM 5.3 The CloudSecure WP Security plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in all versions up to… wordfence
← Prev 1142 1143 1144 1145 1146 1147 1148 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top