πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1152 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a33de35f-1c9d-4fc9-9be8-0a1c7d9352ec
< 2.11.7
MEDIUM 5.3 The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
a32a6ea3-4473-4075-b660-9bba083ae0bf
< 4.3.7
MEDIUM 5.3 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensiti… wordfence
a3271d69-fa4a-42db-8bea-dd54d5a9bc6b
< 1.1.1
MEDIUM 5.3 The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to authorization bypass in all versions up to, an… wordfence
a30f141b-2fd0-448e-88b1-8a334efdfcc7 MEDIUM 5.3 The GZSEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
a2ed23e2-11cc-47b9-bdc7-376c91bc37e9 MEDIUM 5.3 The ThemeRain Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
a2dc1a04-5503-412b-92e7-ed86910abd92
< 2.25.3
MEDIUM 5.3 The GiveWP for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.2. This is d… wordfence
a2d7165b-1290-4032-8fbc-75ec1ab34a08 MEDIUM 5.3 The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5… wordfence
a2a66d58-ee72-49f7-b76b-f8a0f625652c
< 4.7.3
MEDIUM 5.3 The ShopMagic – email automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
a2a41a15-0743-48cc-8c92-7cb839fa5847
< 2.1.0
MEDIUM 5.3 The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2… wordfence
a2935561-6c26-4c22-ab91-a13358a3c978
< 3.5.5
MEDIUM 5.3 The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vul… wordfence
a2919bbc-c4c2-4b52-90ec-2471218cd7d1
< 3.4.0
MEDIUM 5.3 The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur… wordfence
a27c0dc8-a6bf-45a4-af48-ccc375720a4a
< 2.3.4
MEDIUM 5.3 The Kadence Starter Templates β€” Predesigned Website Templates plugin for WordPress is vulnerable to Denial of Service … wordfence
a264eb8a-bf56-4b05-b360-0dd450c70c6b
< 1.11.1
MEDIUM 5.3 The Contact Forms, Live Support, CRM, Video Messages plugin for WordPress is vulnerable to Sensitive Information Exposur… wordfence
a2552407-0b32-4129-b131-792305ed023e
< 6.6.0
MEDIUM 5.3 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to unaut… wordfence
a24e0a05-e387-44be-9a4c-ae59ee65a06a
< 3.4.1
MEDIUM 5.3 The CoSchedule plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
a241252d-684d-4edd-acd1-91a46a5e35fb
< 3.4.3
MEDIUM 5.3 The Sendy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
a2363a40-b627-44da-af8e-98821685c3ea
< 0.2
MEDIUM 5.3 The Eshop Magic plugin for WordPress is vulnerable to Arbitrary File Disclosure in versions before 0.2 via the 'file' pa… wordfence
a1e07c9c-7d35-41b4-aaa1-f37c4f10f7ac
< 2.1.1
MEDIUM 5.3 The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for … wordfence
a1dbd87e-2449-4d59-9f08-f708b93d41cb
< 9.8
MEDIUM 5.3 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to unauthorized access due to a … wordfence
a1d48bf9-5457-4f17-8081-bad01decbf6a
< 2.1.13
MEDIUM 5.3 The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized a… wordfence
a1d42f09-8a2b-47a3-ba35-14c55844f133 MEDIUM 5.3 The Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
a1cf8b8f-bf74-444c-88cc-cc836ee45f26
< 3.2.0
MEDIUM 5.3 The Elements kit Elementor addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
a1b3430b-c502-47f9-bbca-69da1545d221
< 1.8.6
MEDIUM 5.3 The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthor… wordfence
a1af63f6-329e-40b6-b786-302c608ac577
< 2.3.1
MEDIUM 5.3 The Social Media Share Buttons | MashShare plugin for WordPress is vulnerable to Information Disclosure in versions befo… wordfence
a1867c79-29d7-46a4-bfaf-c65e8a44c2ed
< 1.0.9
MEDIUM 5.3 The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on … wordfence
← Prev 1149 1150 1151 1152 1153 1154 1155 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top