πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1169 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
83dcf56d-d483-4fac-8c70-d14a1e6c975d
< 1.0.8
MEDIUM 5.3 The Claspo – Popups, Spin the Wheel & Email Capture plugin for WordPress is vulnerable to unauthorized access due to a… wordfence
83d935fc-7d7b-4c25-97f8-d3fe35307c7a
< 5.1.2
MEDIUM 5.3 The Snow Monkey Forms plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.1.1 … wordfence
83b48cfc-04e7-4929-8da2-cf6beee6d88e MEDIUM 5.3 The CopyRightPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.… wordfence
83b0ae2c-6b08-4b71-a728-c60722ec20c7
< 1.2.61
MEDIUM 5.3 The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and… wordfence
83b03f44-aed4-4f50-94db-8ad1c560be34
< 3.5.8
MEDIUM 5.3 The Facebook for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… wordfence
83ad7ab2-4257-4aac-9388-bfcbc2938984
< 1.7.22
MEDIUM 5.3 Multiple cross-site scripting (XSS) vulnerabilities in the Adminimize plugin before 1.7.22 for WordPress allow remote at… wordfence
83a4caa6-207d-4ca0-bf4e-e7701d9edf91
< 3.2.3
MEDIUM 5.3 The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
83a3ed21-bfef-4aef-a32d-5af5be23a067
< 1.7.8
MEDIUM 5.3 The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthor… wordfence
83a2dcbb-bd7d-49b2-ab90-38e76679ae2f
< 2.7.6
MEDIUM 5.3 The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnera… wordfence
835dd5f5-9517-456e-a48e-6be98b47eaf2
< 3.19.7
MEDIUM 5.3 The Flatsome theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
835353e7-871d-4daf-9ed4-86321daf2366
< 5.1.9.5
MEDIUM 5.3 The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on … wordfence
8342baa8-93b2-4136-9dd9-a66e37b400de MEDIUM 5.3 The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
832e2348-0c1d-4f65-a773-59ae807044e0 MEDIUM 5.3 The School Management System for Wordpress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all… wordfence
8321f68f-da2d-4382-979d-54008de2cae7
< 2.3.6.15
MEDIUM 5.3 The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability… wordfence
830ff660-0265-46e5-8d16-ecd03cdf9f52
< 1.0.5
MEDIUM 5.3 The Importify – Dropshipping WooCommerce Plugin for Aliexpress, Amazon, Etsy, Alibaba, Walmart & More plugin for WordP… wordfence
830a7ca0-a83b-49e9-bbfb-43b509ec4aff
< 2.6.1
MEDIUM 5.3 The Create plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.… wordfence
83048a4b-b64f-43d4-8cd2-f45cccd636f4 MEDIUM 5.3 The Yandex.Metrica plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
8304037f-6d04-4df1-987f-fd62cfec00b3
< 1.3.0
MEDIUM 5.3 The Maya Business Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a… wordfence
82e77268-2437-46a9-989f-ecee9c3e730f
< 2.4.1
MEDIUM 5.3 The follow-my-blog-post plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
82d87c8b-c503-43e8-aba9-cc98427e0859
< 4.5.3
MEDIUM 5.3 The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress… wordfence
82bfdacf-86e1-4383-995e-e757fd389aab
< 0.1.2.0
MEDIUM 5.3 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to unauthorized access due to … wordfence
82bad228-f12a-45ca-a4a4-769f092f4dd8 MEDIUM 5.3 The Userpro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
829a19fc-f262-4b67-b499-76580779eb9a
< 4.0.1
MEDIUM 5.3 The Atarim plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
8292f23c-fb17-4082-9788-f643d1bb097e
< 2.8.2
MEDIUM 5.3 The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.… wordfence
8291fd89-aea1-4f7b-abd8-dee8438c3ed5
< 6.2.8.1
MEDIUM 5.3 The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and i… wordfence
← Prev 1166 1167 1168 1169 1170 1171 1172 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top