πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1155 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9de42bd9-a1d2-48f2-a594-4013a9490e25
< 2.4.7
MEDIUM 5.3 The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inclu… wordfence
9ddcdc04-d381-4870-bc57-af76e0b5185a
< 5.3.0
MEDIUM 5.3 The Highlight and Share – Social Text and Image Sharing plugin for WordPress is vulnerable to unauthorized access due … wordfence
9db178cb-dd83-4bec-9bc0-0e5c4430ba34 MEDIUM 5.3 The Super Custom Login plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
9da7c252-b0d4-4d91-bfc4-fd3c7f667108
< 1.4.4
MEDIUM 5.3 The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Sensitive … wordfence
9da38075-2268-4f98-b02c-0c7c34e16d85
< 1.2.3
MEDIUM 5.3 The Bit SMTP – Easy SMTP Solution with Email Logs plugin for WordPress is vulnerable to unauthorized access due to a m… wordfence
9d847027-0b22-4310-b60e-3bd2ad1940f5
< 5.3.0
MEDIUM 5.3 The Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a… wordfence
9d7ea5b7-a4d5-4d1d-943e-3ba9635f24a1
< 1.10.18
MEDIUM 5.3 The Download Alt Text AI plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
9d720d66-9a2c-4bb7-9be0-341eb0e24193
< 2.2.1
MEDIUM 5.3 The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access d… wordfence
9d6a2238-eca4-4189-a6fe-dd605cd47703
< 0.1.3.8
MEDIUM 5.3 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to unauthorized access due to … wordfence
9d6379b6-9a55-45a5-8308-988b1ee13f52 MEDIUM 5.3 The Universal Clocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
9d604200-91b0-4885-8fe2-1323b9d6fed5
< 3.9.4
MEDIUM 5.3 The WooCommerce Payments plugin for WordPress is vulnerable to payment bypass in versions up to, and including, 4.5.0. T… wordfence
9d56c960-004d-4dde-b0f5-ba32e397e9c3
< 1.3.7.4
MEDIUM 5.3 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
9d0af9d0-eed7-44de-8c2f-2fe6a04d6d0e
< 2.0.10
MEDIUM 5.3 The Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups plugin for WordPress is vulnerable to Sensitiv… wordfence
9d09bdab-ffab-44cc-bba2-821b21a8e343
< 7.6.4
MEDIUM 5.3 The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec… wordfence
9d0154fd-0cab-4445-a92e-c44ae9931479
< 3.5.4.5
MEDIUM 5.3 The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and includin… wordfence
9cf4a11e-ad28-4a93-9278-1d2d113a4859 MEDIUM 5.3 The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, … wordfence
9cf17c08-25b7-450d-acd9-963a1f79e495
< 3.0.0
MEDIUM 5.3 The Redirection for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca… wordfence
9cb25cc5-b8d3-4dbc-b0d3-2a824e34db4f
< 1.9.3.8
MEDIUM 5.3 The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
9ca6f612-a777-4962-848b-2a81bf35ae4c
< 4.3.2.1
MEDIUM 5.3 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due t… wordfence
9c732ea2-0263-4b18-9aa4-29e387b26362
< 2.15
MEDIUM 5.3 The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all versions up to, and includi… wordfence
9c6b570b-2b9d-44d2-8352-59c417393d8a
< 1.0.24
MEDIUM 5.3 The Tiktok Feed plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
9c3a7ca0-9325-4b50-a844-8eeb4047de1a MEDIUM 5.3 The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a miss… wordfence
9c3557a6-aa72-496c-8515-2f6055de6b22
< 3.2.23
MEDIUM 5.3 The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposur… wordfence
9c32e105-5945-49a4-b8c0-7a3076cc58c4 MEDIUM 5.3 The Contact Form – 7 : Hide Success Message plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
9c285682-6e8c-449e-8e43-4ca96fc64b55 MEDIUM 5.3 The Estonian Shipping Methods for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in al… wordfence
← Prev 1152 1153 1154 1155 1156 1157 1158 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top