πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1173 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7d23e7f7-d5fa-4c40-b6ad-70e9ee147c5c
< 7.33.0
MEDIUM 5.3 The Modern Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
7d090e5e-bbcf-4e26-81c5-ed7dcae21f31
< 2.2.6
MEDIUM 5.3 The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all … wordfence
7cfa1b8d-a4cb-4944-8ffa-4060c8f362dd MEDIUM 5.3 The Ultimate Push Notifications ( Mobile / Desktop ), Receive Notification From WooCommerce, BuddyPress, WordPress Defau… wordfence
7cf1a90d-6157-40e7-aed8-4d18bc22432d
< 2.5.6
MEDIUM 5.3 The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… wordfence
7c82577a-e7ee-4549-8d0f-bed09effa035
< 1.3.8
MEDIUM 5.3 The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to unautho… wordfence
7c6c51f1-1a36-494a-abf4-b5f8db030ca6
< 1.2.2
MEDIUM 5.3 The Cookie-Script.com plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
7c4c6b46-0858-46c0-8f33-47d2429d848c
< 8.8.4
MEDIUM 5.3 The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to unauthorized access due to a missing capabil… wordfence
7c336530-09b2-4ead-923f-f1a6266e3e8e
< 3.2.1
MEDIUM 5.3 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i… wordfence
7c2482cc-1717-4fae-b45b-3a1a1ce95fdc
< 29.0.0
MEDIUM 5.3 The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to una… wordfence
7bd43980-9193-4a63-adba-720dd1b11699
< 4.2.7.4
MEDIUM 5.3 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… wordfence
7bb36c0f-68b3-492e-9f08-fe6228b0363f
< 8.0.0
MEDIUM 5.3 The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its public… wordfence
7b851fd6-1477-4370-abf9-42ae2b6f8899
< 5.4.7
MEDIUM 5.3 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database… wordfence
7b7c2644-5409-4a21-ba14-91475cb14cb2
< 4.2.8.4
MEDIUM 5.3 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Exp… wordfence
7b3608ca-8ed6-46ff-8e57-d8b68f91b9f2
< 3.2.85
MEDIUM 5.3 The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in a… wordfence
7b34f50a-4d2d-49b8-86e4-0416c8be202b
< 1.7.3
MEDIUM 5.3 The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Sensit… wordfence
7b33f2ee-3f20-4494-bdae-3f8cc3c6dc73
< 1.9.3.3
MEDIUM 5.3 The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability… wordfence
7b2d1879-c337-41c9-9f47-f9c2fe8e5928
< 7.9.0
MEDIUM 5.3 The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7… wordfence
7b2a3b17-0551-4e02-8e6a-ae8d46da0ef8
< 2.25.1
MEDIUM 5.3 The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca… wordfence
7b23308d-7439-4dd2-9ec7-57b987909121
< 2.8.1
MEDIUM 5.3 WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the u… wordfence
7b22eb82-f073-4adf-8dc6-57025b9bcef8
< 2.6.9
MEDIUM 5.3 The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Sensitive Information Exposure in… wordfence
7b18918f-5a06-4bf7-9b6c-7b8517064f6d
< 1.3.0
MEDIUM 5.3 The Kalon theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in ve… wordfence
7ae5bbd0-2f95-41f3-a484-a9bb21b23b0e MEDIUM 5.3 The BBS e-Popup plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
7ae1e8fd-4d1b-4590-a141-f93d6347c0f2
< 2.3
MEDIUM 5.3 The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all… wordfence
7a71b7e0-0562-4832-ab83-45ba1af57f1c
< 2.22.12
MEDIUM 5.3 The FraudLabs Pro for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
7a6b3ae2-796b-4084-ad19-4b67ea6dea25
< 1.8.6
MEDIUM 5.3 The Qubely plugin for WordPress is vulnerable to unauthorized arbitrary e-mail sending in versions up to, and including,… wordfence
← Prev 1170 1171 1172 1173 1174 1175 1176 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top