πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1151 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a54ad0b4-b6e7-4eac-843e-261ec6c83d84
< 6.3.1
MEDIUM 5.3 The Shortcoder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown… wordfence
a535eb7f-5ec7-4b3b-b46f-4f09434d04b6
< 1.1.0
MEDIUM 5.3 The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a … wordfence
a50f0b34-fce7-4bae-b3da-c2f521d15444
< 3.9.0
MEDIUM 5.3 The PayU CommercePro Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
a4f8585b-5d69-4ef9-a49c-70f59a392ef9
< 2.4.1
MEDIUM 5.3 The WP Job Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
a4e9eabe-21da-4a1a-8896-74020ecb0369 MEDIUM 5.3 Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-… wordfence
a4cf3ab0-7215-43f2-8ad7-c587d3376c26
< 4.2.9
MEDIUM 5.3 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP… wordfence
a4c7c448-fe9d-496d-84f2-0da8d1e13d64 MEDIUM 5.3 The Member Access plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
a4afee53-9bce-4534-aa7e-119504cadc8a MEDIUM 5.3 The Court Reservation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
a49dd64b-6ae8-49ed-9e8a-e5b73c2acf4b
< 3.9.8
MEDIUM 5.3 The MetForm Pro plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 3… wordfence
a440c03b-e626-4e24-9770-7f8e515e2905 MEDIUM 5.3 The DesignThemes Booking Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
a41684e4-574a-4adc-8627-de6040043198 MEDIUM 5.3 The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to unauthorized access due t… wordfence
a40cb2da-dc13-4e20-9602-a4e6c2eade43
< 1.24.1
MEDIUM 5.3 The Forminator plugin for WordPress is vulnerable to a race condition in versions up to, and including, 1.23.3. This is … wordfence
a3ed9841-eecb-4d27-9ed2-44d3100d241d
< 2.5.13
MEDIUM 5.3 The Breeze Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
a3e33a5c-df7c-4ef5-a59c-1c31abcda6d1
< 1.3.5
MEDIUM 5.3 The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to information disclosu… wordfence
a3c5d4ed-7a17-4158-b039-322f729dbdde
< 3.8.2
MEDIUM 5.3 The Captcha plugin for WordPress is vulnerable to captcha bypass in versions up to, and including, 3.8.1. wordfence
a3c515e2-dc69-4686-b60f-413542bf2118
< 2.4.1
MEDIUM 5.3 The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profi… wordfence
a3c3c740-8ebe-44b2-a0ba-6beffe970cf1 MEDIUM 5.3 Directory traversal vulnerability in the Tom M8te (tom-m8te) plugin 1.5.3 for WordPress allows remote attackers to read … wordfence
a3c2cda1-af8c-491c-b376-b39f274fed95
< 4.20.0
MEDIUM 5.3 The Sensei LMS – Online Courses, Quizzes, & Learning plugin for WordPress is vulnerable to Sensitive Information Expos… wordfence
a3ba745a-f13e-4d50-af31-110d8a4eb0e2
< 1.4.11
MEDIUM 5.3 The Posts Table with Search & Sort plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
a3977d10-239d-4b83-ab0c-ad165485498d
< 1.2.64
MEDIUM 5.3 The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions… wordfence
a38ebdeb-6ab8-4f1d-9c13-39211a9e97b6 MEDIUM 5.3 The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up t… wordfence
a376cafb-656c-4fe1-b5c1-c7e38dc5040e
< 1.3.3
MEDIUM 5.3 The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to unauthorized modification of data due to n incorrec… wordfence
a36eb269-c917-4763-86cf-6d533dd906ad
< 2.0.1
MEDIUM 5.3 The Digital Signature Add-on for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all… wordfence
a35fb3c5-7a22-4954-9b4c-eea94fc0fcd4 MEDIUM 5.3 The Felan Framework plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
a3536958-5e11-4dc5-98bc-01fd09ef3090
< 5.2.6
MEDIUM 5.3 The Download Monitor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
← Prev 1148 1149 1150 1151 1152 1153 1154 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top