πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1153 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a152a280-fc36-4211-a4fe-79365b55cae6
< 3.1.8.5
MEDIUM 5.3 The Bricksforge plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… wordfence
a14cce74-6432-4b92-85c8-8b899e4248fd
< 2.2.0
MEDIUM 5.3 The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plug… wordfence
a144c9ae-dfdb-4ea2-8c27-84d59439c72a
< 3.3.14
MEDIUM 5.3 The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plug… wordfence
a12d2c25-7701-4928-a875-c94656b7f7f3 MEDIUM 5.3 The Real Estate Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
a11083dd-7a5f-483b-a854-2697ddc54262
< 3.1.2
MEDIUM 5.3 The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosu… wordfence
a1069b36-3e9a-43ef-8ea1-9a77daf71dcc
< 2.13.0
MEDIUM 5.3 The PowerPack Pro for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
a104f88b-deae-465d-b4c1-9a1fc78e5ee9
< 3.14.0
MEDIUM 5.3 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of dat… wordfence
a0f38af7-7753-4dbe-a4fd-e9a01785dd13 MEDIUM 5.3 The Secure Admin IP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
a0f0bc3e-24d6-48da-8398-42b9abb10f56 MEDIUM 5.3 The Truepush – Most Affordable Web Push Notifications plugin for WordPress is vulnerable to unauthorized access due to… wordfence
a0da1ed2-3ffc-4da8-a8b4-8f5544ed157b
< 1.10.0
MEDIUM 5.3 The USPS Shipping for WooCommerce – Live Rates plugin for WordPress is vulnerable to Sensitive Information Exposure in… wordfence
a0d44294-be44-4e80-9974-9074807a421f
< 2.1.0
MEDIUM 5.3 The Addi – Cuotas que se adaptan a ti plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
a0906540-46fc-4f76-9265-cb87c6340fad MEDIUM 5.3 The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
a054394c-07fa-4961-89f0-1d0fceac736b
< 2.9.3
MEDIUM 5.3 The Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More plugin for WordPress is v… wordfence
a03b4c19-85fa-47ad-b9ae-b466f8e5ca96
< 1.7.7
MEDIUM 5.3 The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized plugin setting changes due… wordfence
a02d9a01-1104-4935-8074-af4367c66278
< 4.3.2
MEDIUM 5.3 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP… wordfence
a01e7b21-f3ff-42a8-b78a-ad69973eda01 MEDIUM 5.3 The Katalogportal PDF Sync plugin for WordPress is vulnerable to Missing Authorization in all versions up to and includi… wordfence
a01141ed-9b9c-426f-96b3-c6ceade4d35c
< 1.1.0
MEDIUM 5.3 The Webflow Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unkn… wordfence
9ffc69f0-125d-4800-a21d-755219b7eb91 MEDIUM 5.3 The Mogi theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in ver… wordfence
9ff499b1-eaf2-4637-9290-9a930256a9d2 MEDIUM 5.3 The Formstack Online Forms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
9fec8d09-6114-49cc-a2fe-7c7b09d13237 MEDIUM 5.3 The MSTW CSV EXPORTER plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
9fda5e15-fdf9-4b67-93d3-2dbfa94aefe9 MEDIUM 5.3 All known versions of WordPress Core store cleartext wp_signups.activation_key values (but stores the analogous wp_users… wordfence
9fd9c076-d36c-4cda-b636-aa65195956d2
< 3.7.4
MEDIUM 5.3 The Coming soon and Maintenance mode plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, an… wordfence
9fd84f6c-2a24-4e0c-b388-0edc5d56a431
< 5.28.5.1
MEDIUM 5.3 The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
9fbee4da-ec75-4bb2-8431-7ab088661d23 MEDIUM 5.3 The Orchid Store theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
9faee46e-f43f-4af6-81f4-500933ffd01f
< 2.3.15
MEDIUM 5.3 The User Access Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
← Prev 1150 1151 1152 1153 1154 1155 1156 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top