πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1162 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9149d2c6-b6c7-430d-8886-c8c5de483220
< 15
MEDIUM 5.3 The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthoriz… wordfence
90f62ee2-f2a8-49e6-ba7a-8c408c66c456
< 1.11.5
MEDIUM 5.3 The Masteriyo - LMS plugin for WordPress is vulnerable to unauthorized access of dat due to a missing capability check o… wordfence
90d8e345-b549-493b-a84b-abe56ab42a04 MEDIUM 5.3 The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including … wordfence
90c6fd67-2140-4835-98d0-cfd1af95ac4c
< 0.1.3
MEDIUM 5.3 The Content No Cache: prevent specific content from being cached plugin for WordPress is vulnerable to Information Expos… wordfence
90c0e937-19fd-484e-a50f-42b00a6eeb30
< 1.0.190
MEDIUM 5.3 The Moosend Website Connector plugin for WordPress is vulnerable to authorization bypass due to a missing capability che… wordfence
90c0be4a-1146-4a17-918e-ed5362bde022
< 1.31.1.1
MEDIUM 5.3 The VK Block Patterns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
90a5589f-f0e9-4511-9c5e-0afcee0824d5
< 10.3.3
MEDIUM 5.3 The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, … wordfence
909b5421-210d-427a-94a0-e1ea25880cec
< 6.1
MEDIUM 5.3 The Formidable Forms plugin for WordPress is vulnerable to IP Spoofing in versions up to, and including, 6.0.1 due to a… wordfence
9099d421-3407-45c3-a1f3-1e1084ec65cb MEDIUM 5.3 The NS Maintenance Mode for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t… wordfence
908df18e-7178-4d40-becb-86e1a714a7da
< 2.5.33
MEDIUM 5.3 The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access o… wordfence
9082adc5-508d-47ac-a74a-868e2600e3d6
< 3.7.7
MEDIUM 5.3 The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Denial of Service in all versions up … wordfence
9079f511-c53d-4721-b975-929a81df8d92
< 6.0.12
MEDIUM 5.3 The AdForest theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
90637d9c-88af-443e-aaa8-4ebcb65b3cef
< 6.20
MEDIUM 5.3 The Ebook Store plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
904f8881-1513-43b7-a9cf-1b81d8493b12 MEDIUM 5.3 Cross-site scripting (XSS) vulnerability in xd_resize.php in the Contact Form by ContactMe.com plugin 2.3 and earlier fo… wordfence
904b9aed-0bd6-414e-a347-3881188a04cf MEDIUM 5.3 The User Spam Remover plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… wordfence
903161b0-b64c-4986-8c94-b90221bc911b MEDIUM 5.3 The Redirects plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on tan unknown… wordfence
9026b417-4b35-4bec-9dc6-6797661dc7a8
< 1.9.0
MEDIUM 5.3 The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulne… wordfence
901d7f63-3c3f-453e-9b6a-85441c1a04c8 MEDIUM 5.3 The Spice Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
8ffdcc0f-8214-4056-abe1-926ed255e9f0
< 4.1.1
MEDIUM 5.3 The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to authorization bypass due to a missing c… wordfence
8ff66981-68ed-489a-b53f-4a1029e7590e
< 23.4
MEDIUM 5.3 The Frontend File Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
8feabfb4-d094-467e-a1b7-266631a04c2f
< 3.1.2
MEDIUM 5.3 The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is… wordfence
8fe397d3-68de-4358-8490-8fbafa1908ef
< 3.9.4
MEDIUM 5.3 The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec… wordfence
8fc6d3e0-3e64-4a75-82a1-ca988b72b953 MEDIUM 5.3 The BoomDevs WordPress Coming Soon Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… wordfence
8fb6c221-d885-42b5-977c-39e8608e3e31
< 1.13.5
MEDIUM 5.3 The Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page plugin for WordPress is vulnerable to una… wordfence
8f906e8c-0b20-4da7-86b8-3306f36c46a4
< 1.6.12.0
MEDIUM 5.3 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to u… wordfence
← Prev 1159 1160 1161 1162 1163 1164 1165 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top