πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1159 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9659c277-e028-4544-bf67-61916dcc1e94 MEDIUM 5.3 The Constructor theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'debug… wordfence
965582c6-a52e-4f88-81ef-b5dd761a0c23
< 2.57
MEDIUM 5.3 The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t… wordfence
965107bd-e1ee-4a0c-af9e-bdd765d3eab5
< 4.1.1
MEDIUM 5.3 The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to authorization bypass due to a missing c… wordfence
963a9b30-9194-4abc-aa69-eb333cbddef3
< 1.30
MEDIUM 5.3 The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to generic SQL Injection via the β€˜sSearch’ paramete… wordfence
9614aaa9-d343-4fd4-8a40-7366cd961bd3
< 1.5.7.7
MEDIUM 5.3 The Simply Schedule Appointments plugin for WordPress is vulnerable to sensitive information exposure in versions up to,… wordfence
96035f77-a707-4538-aea3-88077858ab9b MEDIUM 5.3 The Optimize More! – Images plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
95f49cbd-a794-4b39-92cb-9d9c8df82685
< 4.16.3
MEDIUM 5.3 The GiveWP plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.16.2… wordfence
95d85e42-4872-4fc4-9e6f-4b9d9fb75ef2
< 2.7.3
MEDIUM 5.3 The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnera… wordfence
95cb607f-f110-416b-b9e4-87a68710f230
< 7.106
MEDIUM 5.3 The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
95ca322f-3965-4635-8cbd-8764205d7928
< 1.4.2
MEDIUM 5.3 The Fota WP theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … wordfence
95abec2d-a03a-4b07-8890-18568650c41f
< 2.22
MEDIUM 5.3 The Gift Up Gift Cards for WordPress and WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
95ab7473-e368-47ad-a8a0-0efbdafce562 MEDIUM 5.3 The Social Images Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
95a01f44-2356-4ea4-b48e-80e3c6114efa
< 1.6.6
MEDIUM 5.3 The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
959846a3-0e57-4227-a52b-942b589596f0
< 4.29.5
MEDIUM 5.3 The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Li… wordfence
9576408b-d048-4e36-bc1a-c01c9f586365
< 5.0
MEDIUM 5.3 The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to arbitrary file downloads… wordfence
956f2f87-e33e-4561-8e95-b861a2286f01
< 8.8.4
MEDIUM 5.3 The Simple Link Directory plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
952a3e52-4e23-4bc4-92d3-e15ae2f3d28b
< 3.6.26
MEDIUM 5.3 The Ninja Forms plugin for WordPress is vulnerable to denial of service in versions up to, and including, 3.6.25. This i… wordfence
9516e64c-1959-4980-9a96-c6f5f1baa6f6
< 3.3.5
MEDIUM 5.3 The EventPrime plugin for WordPress is vulnerable to booking price manipulations due to insufficient validation and cont… wordfence
95103830-9009-48df-ab15-476402b59e3f
< 2.9.0
MEDIUM 5.3 The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plug… wordfence
950ef9f8-2700-4bab-90af-154fc9ed5bc6
< 1.0.52
MEDIUM 5.3 The Timetics – Appointment Booking Calendar & Scheduling System plugin for WordPress is vulnerable to unauthorized acc… wordfence
94fd4626-6ff9-449b-8894-f974c8c5ace0
< 1.6.1
MEDIUM 5.3 The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
94fc7e20-0fd1-4a10-b821-e5aba4512f3f
< 10.30.25
MEDIUM 5.3 The Salon Booking System – Free Version plugin for WordPress is vulnerable to Insecure Direct Object Reference in all … wordfence
94f3b21d-1910-46e9-af89-4602099f207c
< 1.9.26
MEDIUM 5.3 The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to Sensitive I… wordfence
94e541ad-83dd-40eb-ab9e-e675e4021c3a
< 3.0.3
MEDIUM 5.3 The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
94c8979a-db2e-490f-b055-cdf19a48cf73
< 4.2.0
MEDIUM 5.3 The Defender Security – Malware Scanner, Login Security & Firewall plugin for WordPress is vulnerable to Sensitive Inf… wordfence
← Prev 1156 1157 1158 1159 1160 1161 1162 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top