πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1168 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8548a8c6-3acf-4de5-a1e9-e3fe5dc8abf1 MEDIUM 5.3 The FullCalendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
852b1895-3bed-4c2f-912c-c136b38a09bb
< 2.12.7
MEDIUM 5.3 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulner… wordfence
85290224-a051-4913-83c7-f54f2b67621e
< 4.0.1
MEDIUM 5.3 The Social Media Widget plugin for WordPress is vulnerable to Spam Link Injection in version 4.0. This is due to a hidde… wordfence
85025fb9-6e19-4c0f-bf16-4b890ba5f7f5
< 3.7.9
MEDIUM 5.3 The ElementsKit Elementor addons Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
85013657-51a6-4d7f-bb9a-aca52d8669bf
< 3.13.3
MEDIUM 5.3 The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
84f65255-f710-44f9-9f77-61776a40abae
< 6.1.0
MEDIUM 5.3 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct … wordfence
84e70472-26a4-4d9a-b1c8-15ab3827c690
< 2.5.1
MEDIUM 5.3 The Gutenverse Companion plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
84e341ec-f93b-4d10-a603-b1c804d46347
< 1.2.5
MEDIUM 5.3 The Masterstudy Elementor Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
84e269dd-05bd-4671-802d-b21e4987b3f0
< 3.4.3
MEDIUM 5.3 The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure… wordfence
84d55f24-c4de-4574-b0cc-cc1b4935d281
< 2.0.7
MEDIUM 5.3 The PropertyHive plugin for WordPress is vulnerable to unauthorized access of premium features due to a missing capabili… wordfence
84c57acb-e19b-4efa-95a2-82219b20964e
< 4.24.5
MEDIUM 5.3 The Sensei LMS – Online Courses, Quizzes, & Learning plugin for WordPress is vulnerable to unauthorized access due to … wordfence
84a5348a-a307-4db4-83b6-08682282a4b8
< 4.1.16
MEDIUM 5.3 The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to… wordfence
8498c671-b46e-420c-a482-7c6983596753
< 1.0.43
MEDIUM 5.3 The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of … wordfence
849127cc-0b28-4673-addc-100a7d232798
< 1.19.5
MEDIUM 5.3 The Mail Mint – Newsletters, Email Marketing, Automation, WooCommerce Emails, Post Notification, and more plugin for W… wordfence
84878b9c-c13c-44d5-a39d-6befd51a14ff
< 5.5.81
MEDIUM 5.3 The WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards plugin for WordPress is vulnerable to un… wordfence
8472c1ae-5db2-4ff6-abf3-f9088fc6f531
< 1.1.16
MEDIUM 5.3 The Pallet Packaging for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabili… wordfence
8470b7be-6fae-4941-b523-93e230366522
< 7.2.2.3
MEDIUM 5.3 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure… wordfence
846f9828-2f1f-4d08-abfb-909b8d634d8a
< 2.10.0
MEDIUM 5.3 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
84598365-dd46-424b-b6ff-6b8880cadb57 MEDIUM 5.3 The Biolife theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
8445f318-ef4e-45c5-be9b-6080833c3bb6
< 5.2.02
MEDIUM 5.3 The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Login Page Disclosure in all versions… wordfence
8444429e-147f-434d-9602-e4a1e05f4a09
< 2.4.4
MEDIUM 5.3 The Homey Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
842f3cb4-857e-4e9c-b84e-9a47ec65db0d MEDIUM 5.3 The PopAd plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. … wordfence
841a028d-ff36-4e3f-903b-e25951648075 MEDIUM 5.3 The AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations plugin for WordPress is vulnerable to… wordfence
8405e80d-fd72-4d87-b08a-19a686eb2982 MEDIUM 5.3 The Easy Theme Options plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,… wordfence
83eee860-ce3a-419c-937f-0fa24e04b04b MEDIUM 5.3 The WP Advanced PDF plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
← Prev 1165 1166 1167 1168 1169 1170 1171 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top