πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1157 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
99778d0b-1909-4075-8b80-531b67e7ed79
< 1.0.12
MEDIUM 5.3 The Shopwell theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
996b44bb-d1e0-4f82-b8ee-a98b0ae994f9
< 4.13
MEDIUM 5.3 The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
99650c4d-d8ef-4970-af65-b22b7fdf3543
< 2.3.5
MEDIUM 5.3 The wpForo Forum plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… wordfence
99623228-e199-44a9-b20f-b1d351720a8d
< 6.6.19
MEDIUM 5.3 The CTX Feed plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
995a6c1d-fb49-4953-9828-f6594ac45fa7
< 1.2.7
MEDIUM 5.3 The Contact Form 7 Database Addon – CFDB7 plugin for WordPress is vulnerable to Sensitive Information Exposure in vers… wordfence
9956e04c-ff59-40c0-a8ab-3e2ed2c52d7f
< 9.0.5
MEDIUM 5.3 The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.… wordfence
991d63da-ca6c-400e-beb7-b44cf629abc9
< 5.2.8
MEDIUM 5.3 The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions … wordfence
990d62fd-dc55-446e-b3ff-52c7c121aeb8
< 3.1.25
MEDIUM 5.3 The Icegram plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the d… wordfence
98ef80a3-4d57-45ae-87cf-d5768b26c27e
< 3.3.3
MEDIUM 5.3 The EventPrime plugin for WordPress is vulnerable to booking payment bypass in all versions up to, and including, 3.3.2.… wordfence
98e8e09c-f2fe-40ab-b1ce-62a1627b6b65
< 3.12.0
MEDIUM 5.3 The CoCart – Headless ecommerce plugin for WordPress is vulnerable to unauthorized access of data, modification of dat… wordfence
98d008a4-5dbf-410f-8753-d5aeb28b4447
< 1.45.1085
MEDIUM 5.3 Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allo… wordfence
98c4cecd-97e8-4f40-bd70-c05d9c85f3c2
< 2.0.0
MEDIUM 5.3 The B Slider – Responsive Image Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
98a7572d-9642-4150-8112-c0fa2b25ae05 MEDIUM 5.3 The CallbackKiller service widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
989f4c4b-e0d6-4755-89ef-6cf4624f5473
< 4.5.0
MEDIUM 5.3 The Sensei LMS plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 4.4.3. Th… wordfence
989e666c-4187-4220-9c1b-dd43c8a72c70
< 1.17.3
MEDIUM 5.3 The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Se… wordfence
98994c7d-87a0-4b35-beb4-34f4c140dac9
< 1.7.1
MEDIUM 5.3 The REST API Log plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.7.0. This… wordfence
98907ef3-7c54-4d08-9eb4-2409f1de893f MEDIUM 5.3 The Wide Banner plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
988c30f7-5f04-4ee5-b3d5-0dd66d23e1cc
< 1.0.7
MEDIUM 5.3 The FormLayer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
9871f683-136e-45b5-90fb-a373a771014b
< 3.7.4.1
MEDIUM 5.3 The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPre… wordfence
98719f12-d100-4f72-a8fa-61205a24784d
< 10.30.26
MEDIUM 5.3 The Salon Booking System – Free Version plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
986e0252-b94d-4ac8-9083-0218fa8a651e
< 8.7.12
MEDIUM 5.3 The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mis… wordfence
985fdf6e-5070-48da-8cee-6ec3f2fecda4
< 1.9.7
MEDIUM 5.3 The FV Simpler SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
98386090-ff19-4e02-9f19-428da4494220 MEDIUM 5.3 The XML Multilanguage Sitemap Generator plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
981ed50b-8f03-4320-99f0-3f53f7b2fc44
< 1.7.1
MEDIUM 5.3 The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modi… wordfence
980b16d4-3c4a-4ed1-af46-f39f3ec6dd19
< 3.2.2
MEDIUM 5.3 The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST … wordfence
← Prev 1154 1155 1156 1157 1158 1159 1160 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top