πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1158 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
97f7cdf1-1439-40b3-90de-cdf19de4108a
< 4.5
MEDIUM 5.3 The Wawp plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in ve… wordfence
97e9c99f-e143-42db-a02a-1467276e32b1
< 8.3.2
MEDIUM 5.3 The Nexi XPay plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
97e863fd-0256-421e-8a3d-ef9460248d2e
< 3.0
MEDIUM 5.3 The Neon Channel Product Customizer Free plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
97dd7e1a-9189-4a35-9cd0-e80b5d9a0e9f
< 3.5.5.5.2
MEDIUM 5.3 The Passster plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.5.5.5.1 d… wordfence
97c46a13-6981-426f-b24a-c9820657042f
< 3.4.9
MEDIUM 5.3 The Banhammer – Monitor Site Traffic, Block Bad Users and Bots plugin for WordPress is vulnerable to Blocking Bypass i… wordfence
97b9cfa8-0bb4-47ac-b811-514c0d76d8ef
< 10.30.34
MEDIUM 5.3 The Salon Booking System – Free Version plugin for WordPress is vulnerable to Sensitive Information Exposure in versio… wordfence
97b327cc-7a72-4cc3-a4db-a693469f6917
< 1.5.0
MEDIUM 5.3 The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
97ab2585-4178-4a5b-923f-2ce9ca44a8d7
< 3.7.10
MEDIUM 5.3 The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not u… wordfence
979962e3-9052-4dc9-94d0-3ec8de3d5460
< 1.1.8
MEDIUM 5.3 The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all ver… wordfence
97553155-c425-4ea1-964a-b5df4263161b
< 1.7.3
MEDIUM 5.3 The Stop User Enumeration plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and i… wordfence
975293a1-7b69-4e10-93a3-74c00562c758
< 1.5.0
MEDIUM 5.3 The Shared Counts – Social Media Share Buttons plugin for WordPress is vulnerable to unauthorized access to functional… wordfence
9734a4e0-04f9-478e-9bb9-5127671bf8f6
< 1.4
MEDIUM 5.3 The Easy PayPal Events & Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
97174ec0-a2b7-455e-9bf8-b6f51546beee
< 4.0.4.4
MEDIUM 5.3 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Pr… wordfence
970bc71c-7d0a-4761-874a-379cda71418e
< 3.1.0
MEDIUM 5.3 The My Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl… wordfence
96f1bb31-5723-4de3-a063-49099c8c1b8d
< 1.1.13
MEDIUM 5.3 The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized acces… wordfence
96dfba93-6e63-4d6d-982d-8aa6d77346a6
< 2.3.0
MEDIUM 5.3 The DMCA Protection Badge plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
96d48392-fb64-4e5e-be9c-21df0bf75de6
< 2.0.26
MEDIUM 5.3 The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da… wordfence
96bd997f-63d5-47a7-b433-486c1113b44b
< 2.1.16
MEDIUM 5.3 The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized m… wordfence
96bc27f3-6aa4-4119-9978-5e9dee5f1796
< 6.4.9.5
MEDIUM 5.3 The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th… wordfence
96ab5bb0-724c-434b-acc4-be8265b4838f MEDIUM 5.3 The WP Post Rating plugin for WordPress is vulnerable to unauthorized modification of votes in versions up to, and inclu… wordfence
96a8fc8b-6f0a-486c-89d1-7211b4ca31bd
< 2.8.1
MEDIUM 5.3 The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to … wordfence
9697fa6d-9356-4d9d-b8cd-ba933674b213
< 1.6.1
MEDIUM 5.3 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to open registration in all versions up to, a… wordfence
9694f4e0-be99-4122-82d2-b22e7422c877 MEDIUM 5.3 The Event Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
9666913e-55a3-441c-85ef-8a12756e37ba
< 2.3.4
MEDIUM 5.3 The User Activity Log Pro plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.… wordfence
965bb642-4472-491f-8378-f4331ba4ab7c MEDIUM 5.3 The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … wordfence
← Prev 1155 1156 1157 1158 1159 1160 1161 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top