πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1149 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a99456c4-c828-4dc9-9375-8981eafbeb15
< 1.4.5
MEDIUM 5.3 The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is v… wordfence
a91e20c4-86f2-42d4-9c65-4eccf3a24e3f
< 3.0.5
MEDIUM 5.3 The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
a917a24b-09cc-48e9-844a-e1ed573a708f
< 2.4
MEDIUM 5.3 The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorize… wordfence
a916d3d1-71c4-4443-b6cf-0c3a8b56feee MEDIUM 5.3 The Do Lasso plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 35… wordfence
a902e759-c55a-4c24-a0db-d1a49f3dee5a
< 3.4.3
MEDIUM 5.3 The Noptin plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient controls on the p… wordfence
a8f093bc-5cd3-41a0-b86b-d00338334d2e
< 2.15.12
MEDIUM 5.3 The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… wordfence
a8e744b3-0c4a-492a-9102-5dff10f850b0
< 1.0.1
MEDIUM 5.3 The Floating Action Buttons plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
a84a4c56-a44e-450d-91fc-024f8ddeedee
< 2.2.7
MEDIUM 5.3 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
a82ac1c9-e037-4afa-b433-2efef2e61403
< 7.6.3
MEDIUM 5.3 The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching boo… wordfence
a813251b-a4c1-4b23-ad03-dcc1f4f19eb9
< 3.8.1
MEDIUM 5.3 The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… wordfence
a7cf1c70-9778-4b50-b494-d0b1d0277b35
< 3.9.5
MEDIUM 5.3 The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & El… wordfence
a7c786fe-898e-4478-97b9-c1fb41c9081c
< 2.2.7
MEDIUM 5.3 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
a7c10b81-bdbb-4089-8d89-42ad2a1fa78f MEDIUM 5.3 The CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress plugin for WordPress is vulnerable to CAPTCHA Bypass in all … wordfence
a7beb9b3-3e4e-4aa2-b174-ecd9307cb3d0
< 1.1.4
MEDIUM 5.3 The Redirect Redirection plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capabili… wordfence
a7b25b66-e9d1-448d-8367-cce4c0dec635
< 4.0.12
MEDIUM 5.3 The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil… wordfence
a7ad5c95-f092-4951-b87c-9a29b21b7a6e
< 1.2.6
MEDIUM 5.3 The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable… wordfence
a79b37b0-e5b1-4018-a0ef-97aa22f37599 MEDIUM 5.3 The WP Gmail SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
a793b24f-979e-4209-93f7-cff8d3867a7d
< 1.2.21
MEDIUM 5.3 The atec Duplicate Page & Post plugin for WordPress is vulnerable to unauthorized post duplication due to missing author… wordfence
a7701dd2-8452-4529-a931-db2553ca1ae5
< 3.2.5
MEDIUM 5.3 The Yoast SEO plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including 3.2.4. This… wordfence
a75b8e3a-6ce2-4257-beb7-6cf94e5285c4 MEDIUM 5.3 The School Management plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and incl… wordfence
a72639df-fa05-414c-b30c-eb285f59d945
< 3.7.15
MEDIUM 5.3 The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in a… wordfence
a720ad0e-6194-4df4-951e-e818518e79b5
< 1.0.65
MEDIUM 5.3 The BookingPress plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, … wordfence
a712c529-b69d-4acf-b55a-64fb3a45b990
< 1.1.3
MEDIUM 5.3 The Ksher plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in a… wordfence
a70a91f3-ec87-472a-9cb0-98c874b7825f
< 1.8.1
MEDIUM 5.3 Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows … wordfence
a7041b6c-b76d-46ee-a2d5-68378ee7f7b6
< 1.3.8
MEDIUM 5.3 The iPOSpays Gateways WC plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.3… wordfence
← Prev 1146 1147 1148 1149 1150 1151 1152 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top