πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1147 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ad5782d6-f36b-4b7d-b6c0-b9329fb8725c
< 3.1.25
MEDIUM 5.3 The Icegram plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
ad4e5243-e41a-4624-b9cd-47ab79637560
< 3.9.9
MEDIUM 5.3 The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
ad2d5070-ddc6-4478-abe5-776e197a4507
< 3.2.8
MEDIUM 5.3 The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all v… wordfence
ad2b053b-12c0-42fa-b3da-31c824f04848
< 0.7.9
MEDIUM 5.3 The Link Whisper Free plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… wordfence
ad2af511-a038-47bf-b9ec-b464cb28593d MEDIUM 5.3 The Bux Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
ad12941f-8cbf-41c6-a261-b47075198d26 MEDIUM 5.3 The Sandbox theme for WordPress is vulnerable to Full Path Disclosure in versions up to, and including 1.6.1 via the che… wordfence
acd85c0c-7f48-4b09-a44f-7f0858c68616 MEDIUM 5.3 The Funnelforms Free plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
acc88688-76e0-4477-8b7c-eeff541881ab
< 0.3.9
MEDIUM 5.3 The Payaza plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … wordfence
acb5b0e2-7a12-4c7e-b316-b03ae9b605fc MEDIUM 5.3 The Restore PayPal Standard for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in versions up to, and … wordfence
ac7d08e6-b04d-4b8c-af43-1abe8b531f7c
< 4.7.8
MEDIUM 5.3 The Simple Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
ac5f5093-a0c6-43bd-8e89-7fe5d90a779b
< 1.6.9
MEDIUM 5.3 The Product Addons and Product Options With Custom Fields – WowAddons plugin for WordPress is vulnerable to unauthoriz… wordfence
ac402867-baa3-412c-b5de-c01e6a790ded MEDIUM 5.3 wp-php-widget.php in the WP PHP widget plugin 1.0.2 for WordPress allows remote attackers to obtain sensitive informatio… wordfence
ac11bd41-d6bf-47e7-87a7-b45d7cb80639
< 2.1.7
MEDIUM 5.3 The Kit (formerly ConvertKit) for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in al… wordfence
ac06b9d9-51de-4f7a-87b8-c7b46a8475ee
< 1.5.3
MEDIUM 5.3 The Site Offline plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 1.4.9. … wordfence
abeb13ac-d835-4e02-baaf-30e8dc4bd86b
< 4.2.9
MEDIUM 5.3 The Primer MyData for Woocommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and includ… wordfence
abe1b727-cd92-43aa-8b6e-e02befa53195
< 1.0.8
MEDIUM 5.3 The WPBookit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
abc983c6-aa30-4d1b-b6af-99b5ba1c8481
< 1.2.19
MEDIUM 5.3 The iQ Block Country plugin for WordPress is vulnerable to Country Blocking Bypass in versions up to, and including, 1.2… wordfence
abc3f352-8568-4649-bf3c-dd0ce0295589
< 2.9.31
MEDIUM 5.3 The Affiliates Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i… wordfence
abc0d9c0-ed5a-4bb8-9ff1-d2833dd04d31
< 20260217
MEDIUM 5.3 The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Sensitive Information Exposur… wordfence
abb41236-d711-41d3-a1cd-2c23467e269a
< 2.0
MEDIUM 5.3 The Aspose Cloud eBook Generator plugin for WordPress is vulnerable to Directory Traversal in versions up to, and includ… wordfence
abb362f1-8782-4217-a231-c9b258da6964
< 34.0.0
MEDIUM 5.3 The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to unauthorized access du… wordfence
ab96123e-17aa-461f-b460-e8eba82c78e1 MEDIUM 5.3 The Localize Remote Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
ab8bb8b3-59a6-424a-bc7b-b8740c936637
< 1.33.1
MEDIUM 5.3 The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to Sensitive Information Ex… wordfence
ab87321b-d326-498d-9a75-44692258cae6
< 4.21.0
MEDIUM 5.3 The FG Joomla to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… wordfence
ab87210f-1f21-4208-ab50-4f62ec8e02fb
< 5.1.1
MEDIUM 5.3 The Simple Social Media Share Buttons – Social Sharing for Everyone plugin for WordPress is vulnerable to Sensitive In… wordfence
← Prev 1144 1145 1146 1147 1148 1149 1150 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top