πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1160 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
94aca289-e242-4b0c-9bd8-cc77b1d26b34
< 5.7.8
MEDIUM 5.3 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to a Race Condition in … wordfence
9481a3a6-6d79-4246-852e-f664f578ee71
< 7.8.10.2
MEDIUM 5.3 The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized acces… wordfence
944e4c96-6ded-4483-9eaf-d976646f45ea
< 1.1.7
MEDIUM 5.3 The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions … wordfence
943cd10b-1b58-4803-ba6f-291f73353422
< 5.0.6
MEDIUM 5.3 The Welcome Email Editor plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability ch… wordfence
9428f710-db34-418f-9918-b35609ca5185 MEDIUM 5.3 /payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering i… wordfence
9423858b-74be-4b34-961d-97765d8edcbf
< 5.2.8
MEDIUM 5.3 The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca… wordfence
941d0647-5027-4642-88fc-3ab26acbb639
< 8.3.16
MEDIUM 5.3 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to… wordfence
9410b5b8-1bb2-42d7-8d4d-721131d392e3
< 1.1.4
MEDIUM 5.3 The Change WP Admin Login plugin for WordPress is vulnerable to Protection Mechanism Failure in versions up to, and incl… wordfence
940c6a27-05a2-4eca-89ee-b483f88b9524
< 5.1.20
MEDIUM 5.3 The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data… wordfence
9407c53a-c4b4-4f5a-a516-6fb29eb11836 MEDIUM 5.3 The Checkimate plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.0.13. This … wordfence
93daab72-1243-4a05-91d3-9254a1aac727
< 5.6.5
MEDIUM 5.3 The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions… wordfence
93aeb280-1ce0-419d-947e-ec4b06a40307
< 1.3.0
MEDIUM 5.3 The Bakes And Cakes theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
93a698df-fd68-4fbc-946e-a9b5a7f93b71 MEDIUM 5.3 The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to unauthorized… wordfence
9395585d-e0cd-41f5-af29-328fdaf8b600 MEDIUM 5.3 The WordPress Adverts Plugin – Adverts Click Tracker plugin for WordPress is vulnerable to unauthorized access due to … wordfence
938f0ac2-6454-472b-8119-4ffaa7a3670c
< 5.0.8
MEDIUM 5.3 The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
9383627d-901d-4c2a-965c-f9b8ddd38a4b
< 4.0.1
MEDIUM 5.3 The GSheetConnector For WPForms plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
9370cf3f-27bd-42f7-bd0c-88dcb86fd459 MEDIUM 5.3 The Civi - Job Board & Freelance Marketplace WordPress Theme theme for WordPress is vulnerable to unauthorized access du… wordfence
935f5d76-d63a-4db4-b645-b7961ae8bfaf
< 5.5.69
MEDIUM 5.3 The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc… wordfence
9355b100-08a9-4640-a91b-e56ba1ab9b07 MEDIUM 5.3 The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions… wordfence
934fd6a8-7d94-4127-9a00-1ea2f0c66cdd
< 12.6.0
MEDIUM 5.3 The Order Delivery Date Pro for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in vers… wordfence
9347900c-61c2-4d63-885e-e971c646b737
< 1.1.11
MEDIUM 5.3 The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to… wordfence
9330ae5a-1f30-4934-ad78-ad1b886de277
< 2.1.13
MEDIUM 5.3 The Property Hive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
92c49231-f042-4ecc-8e31-ffe55b695c73
< 2.4.9.1
MEDIUM 5.3 The JetMenu for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
92b1db98-aa8e-45ab-83c4-495f6390ee17
< 1.3.6
MEDIUM 5.3 The Broken Link Notifier plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
92ab9ad3-1c93-4791-9fc0-a3cf59eca9d8
< 5.0.9
MEDIUM 5.3 The Church Admin plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability … wordfence
← Prev 1157 1158 1159 1160 1161 1162 1163 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top