πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1148 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ab5e166e-12a4-4359-8b27-d5272d4bbd1c
< 1.4.2
MEDIUM 5.3 The Metro Magazine theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
ab5a88a9-55ff-428d-9ce2-3247f5d48266
< 1.2.16
MEDIUM 5.3 The UsersWP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
ab395e85-6d50-4bc3-8471-f7911967408c MEDIUM 5.3 The Lawyer Directory plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
ab2a011e-73c5-4fb9-a8d2-aaa2756d93f9 MEDIUM 5.3 The Widget Manager Light plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
ab051f4a-030a-44aa-8cbf-665c6c6d31a7
< 1.0.17
MEDIUM 5.3 The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthor… wordfence
aaf71daa-2130-47ce-a8b1-85321df954b2 MEDIUM 5.3 The WP AutoKeyword plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
aadf1d59-60ba-4da2-adbb-4e84d587a34d
< 2.4.4.1
MEDIUM 5.3 The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability… wordfence
aad58ed3-9efc-450a-8f19-07ae4b0d7ca7 MEDIUM 5.3 The WP Mailgun SMTP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
aad4b58f-71ed-4192-a936-0fe3bd721b45
< 4.8.5
MEDIUM 5.3 The Contact Form, Drag and Drop Form Builder Plugin – Live Forms plugin for WordPress is vulnerable to unauthorized mo… wordfence
aabf80d4-e7fe-413d-bb7d-9064c0a0a16d MEDIUM 5.3 The iCARRY plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.9. T… wordfence
aaa041a3-d8e5-4637-b8da-5f07c498685a
< 1.6.2
MEDIUM 5.3 The Alt Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknow… wordfence
aa8d746f-82e2-4615-92bb-35d20124dc56 MEDIUM 5.3 The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and c… wordfence
aa85e614-b0e0-4d54-a9f0-27c99e898b7d
< 1.10.0
MEDIUM 5.3 The Contact Form by Supsystic plugin for WordPress is vulnerable to Payment Bypass in all versions up to 1.10.0 (exclusi… wordfence
aa60f16f-bd25-4b8b-9e3c-0996b9e3de42
< 1.10.0.5
MEDIUM 5.3 The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress i… wordfence
aa5c20ff-1c8d-484e-977e-65be2a6c57e5
< 3.0.4
MEDIUM 5.3 The AI Text to Speech – TTS Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access due to a mi… wordfence
aa3e030b-8ef1-4dbc-940d-6c2ab2683620
< 3.6.0
MEDIUM 5.3 The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in a… wordfence
aa26e958-4850-451b-88eb-d48fc0c7feb7
< 7.8.5
MEDIUM 5.3 The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable … wordfence
aa107267-2e67-48bf-968c-7f741ecbd786
< 2.12
MEDIUM 5.3 The Web Accessibility by accessiBe plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions … wordfence
aa07f48f-370f-4985-a6fc-a94ed5c59ed4
< 1.4.5
MEDIUM 5.3 The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulner… wordfence
a9ef7742-e6f8-4350-90e9-242d9d1b12a0
< 3.0.2
MEDIUM 5.3 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulner… wordfence
a9db002f-ff41-493a-87b1-5f0b4b07cfc2
< 4.9.1
MEDIUM 5.3 The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks o… wordfence
a9c4d444-0f55-44b2-b12e-5abc2a30c3fe
< 2.1.1
MEDIUM 5.3 The WC Serial Numbers – Ultimate License Manager for Selling, Licensing & Securely Delivering Digital Content with Woo… wordfence
a9c41797-b256-47de-a783-18df36dd2234
< 1.2.2
MEDIUM 5.3 The Injection Guard plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
a9af78cf-8a04-47a9-8cb5-c276bc504b0f
< 5.0.4
MEDIUM 5.3 The BitFire Security – Firewall, Malware Scanner, Bot Blocker, Login Protection plugin for WordPress is vulnerable to … wordfence
a99ec547-63b5-474b-b6d0-e4ef9c2b4445
< 1.1.4
MEDIUM 5.3 The Sessions Time Monitoring Full Automatic plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
← Prev 1145 1146 1147 1148 1149 1150 1151 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top