🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1150 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a6ff3028-07bb-49c2-b1e4-0f5910a53bd6
< 2.0.8
MEDIUM 5.3 The FileBird Document Library plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to… wordfence
a6f9a9c2-4ef6-4004-afc3-e08cb7f03255
< 1.7.1.1
MEDIUM 5.3 The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to unauthorized modification of data due to… wordfence
a6d5c2be-e4d3-4751-9a49-195270129095
< 2.0
MEDIUM 5.3 The PopCash.Net Code Integration Tool plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
a6d12f0a-dd53-4e0d-9e27-49be5eb1e78e MEDIUM 5.3 The Site Suggest plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
a67e4e4f-0d0f-40bd-9fa6-2c865cfab3d0
< 2.4.7
MEDIUM 5.3 The Konte - Minimal & Modern WooCommerce Theme theme for WordPress is vulnerable to unauthorized access due to a missing… wordfence
a67ab966-c179-4ea6-bf8c-bc22f9b4644b
< 10.3.5
MEDIUM 5.3 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Insecure Direct Ob… wordfence
a671128a-74e6-4f92-94af-9e5e37ed7b7a
< 2.3.3
MEDIUM 5.3 The User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
a669f6ef-0cf1-4fdb-855a-1d6aaa7d8f6c
< 3.1.4
MEDIUM 5.3 The Simply Static plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
a6664039-554b-43bf-8925-00c1e62e28f5
< 1.0.7
MEDIUM 5.3 The WordPress Manutenção plugin for WordPress is vulnerable to IP Spoofing in all versions up to, and including, 1.0.6… wordfence
a65cc674-a0ea-46b9-b609-b184e1f7ca8e
< 7.5.22
MEDIUM 5.3 The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up t… wordfence
a6425d39-cc8b-4130-8f67-2d6de7954934
< 3.4.1
MEDIUM 5.3 The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due t… wordfence
a63f0b4b-ad8f-4daf-9450-133bf08c2de1 MEDIUM 5.3 The WordPress RokBox plugin is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.13 via the erro… wordfence
a6382ebd-f836-4f39-8113-1475163d6b81
< 1.4.38
MEDIUM 5.3 The WowOptin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
a62df5f6-64b0-4489-9dde-0d472040ee12 MEDIUM 5.3 The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … wordfence
a6258be3-2f9e-476d-84d5-5014818ef3ab MEDIUM 5.3 The File Uploader for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and includ… wordfence
a61335cb-024d-4f58-8e58-c5b2064d8b51
< 2.5.3
MEDIUM 5.3 The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
a5ef4d74-aa5d-4d6d-af2c-bda506fb394d
< 2.2.3
MEDIUM 5.3 wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF)… wordfence
a5df5298-21a2-4dbc-b5d5-d7871d77d19e
< 1.9.0
MEDIUM 5.3 The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due t… wordfence
a5ad6de2-b14e-4aaf-855f-f71c324edd68 MEDIUM 5.3 The Stacks Mobile App Builder – The most powerful Mobile Applications Drag and Drop builder plugin for WordPress is vu… wordfence
a5a1ccb2-4f78-4855-a01d-b15f73407822
< 5.1.3
MEDIUM 5.3 The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vu… wordfence
a5991df2-1aab-4d07-9e30-1257aa9ec884
< 2.20.48
MEDIUM 5.3 The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … wordfence
a58a859d-0274-4d2f-80e3-ff30022842c4 MEDIUM 5.3 The The Publisher Desk ads.txt plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
a58080ca-8b07-42ce-8bed-10ad1c028833
< 4.3.11
MEDIUM 5.3 The BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable t… wordfence
a56eae11-578e-40d3-8a89-72af7d4d42e1 MEDIUM 5.3 The Custom CSS and JavaScript plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, an… wordfence
a55e0d63-b844-41a4-bc16-9fd10dfbe9a1
< 1.0.10
MEDIUM 5.3 The HAPPY – Helpdesk Support Ticket System plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
← Prev 1147 1148 1149 1150 1151 1152 1153 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top