πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1164 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8d9720e0-444a-4611-ab8f-33ad005749d5
< 5.3.0.1
MEDIUM 5.3 The Uncanny Automator Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
8d7cc468-eeba-497f-9e11-79d4bebdd7a2
< 2.3
MEDIUM 5.3 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization… wordfence
8d60ddd3-b064-48de-bfd3-baac342150b4
< 2.0.14
MEDIUM 5.3 The Payment Plugins for PayPal WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
8d3d5f62-9e68-4d45-bc3a-b1ac53a05ee4
< 2.9.51
MEDIUM 5.3 The Affiliates Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i… wordfence
8d0fef4d-2c0e-486e-8a55-1c7230636a5c
< 1.3.9
MEDIUM 5.3 The Hostinger Reach – AI-Powered Email Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modi… wordfence
8d08d381-d0ef-4f40-975d-51e919a7c872
< 2.11.0
MEDIUM 5.3 The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2… wordfence
8d07b7c1-8180-4b2a-bf35-2c5b3d419152
< 3.3.07
MEDIUM 5.3 The Download Manager plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, … wordfence
8cff3784-1b3f-45bb-a0b8-481dd24ed67d
< 2.8.1
MEDIUM 5.3 The SureForms Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
8cef4b2b-ae8d-4e18-b763-6960a0b944f7
< 2.8.5
MEDIUM 5.3 The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and inclu… wordfence
8ce1253e-48fe-4005-816c-9cf6127cae54
< 3.2.5
MEDIUM 5.3 The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
8cd7bbfb-57e7-4bee-ad99-b8e9710da81d
< 4.20.0.3
MEDIUM 5.3 The LearnDash LMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
8ccdad2e-66a6-4263-a10e-f7b045d71c0d MEDIUM 5.3 The Plum: Spin Wheel & Email Pop-up plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
8c56e308-cd21-4dd3-ac0a-d9908c8d0819 MEDIUM 5.3 The Support Plus Responsive Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in vers… wordfence
8c38ee66-fd0b-40de-b136-a2c5bf5b37f3
< 7.2.1
MEDIUM 5.3 The Coupon Affiliates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
8c26d080-978b-4a3d-827b-7e9712eb2aad
< 5.0.21
MEDIUM 5.3 The LTL Freight Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to unauthorized loss of data due… wordfence
8c1e1fe4-23be-4f66-ae9f-cabb83811b71
< 2.5.0
MEDIUM 5.3 The Easy Custom Auto Excerpt plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,… wordfence
8c04e40a-6d94-4688-9159-07bf27a9efe0
< 1.9.9
MEDIUM 5.3 The Create by Mediavine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … wordfence
8c009c74-d877-46af-90b3-55292f6b2695
< 2.4.0
MEDIUM 5.3 The Ultimate Review plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
8bfefe86-b25e-4ffe-9beb-28dc22a99d62
< 1.3.2
MEDIUM 5.3 The PayTR Taksit Tablosu plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability c… wordfence
8bdcc0ec-79ce-4108-b60a-5930266bbf48
< 2.2.1
MEDIUM 5.3 The Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More plugin for WordPress is vulner… wordfence
8bd04a52-ed59-4305-831e-646ab5801d36
< 1.4.5
MEDIUM 5.3 The WPS Cleaner plugin for WordPress is vulnerable to Arbitrary Media File Disclosure in versions up to, and including, … wordfence
8bccefbe-2d20-40a7-b24f-d867d80250e3 MEDIUM 5.3 The Libsyn Publisher Hub plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… wordfence
8bb34d74-4d13-4e7a-b78d-5691eb778401
< 4.9.5
MEDIUM 5.3 The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerab… wordfence
8bac8450-7ea9-4859-a8f6-97311345f290
< 1.2.67
MEDIUM 5.3 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordP… wordfence
8b9f171f-56d8-4ab9-bf61-0daa7c0d928f
< 3.11.1
MEDIUM 5.3 The AppMySite – Create an app with the Best Mobile App Builder plugin for WordPress is vulnerable to Sensitive Informa… wordfence
← Prev 1161 1162 1163 1164 1165 1166 1167 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top