πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1177 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
746265fa-151b-4ea8-8871-8828b878da62
< 1.6.1
MEDIUM 5.3 The Unlimited Timeline plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
7448e2bd-07f2-49fe-b094-9d55ea7cbe35
< 2.8.0
MEDIUM 5.3 The The Grid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
7430594c-3a71-4b24-875b-014e03be868f
< 2.4.13
MEDIUM 5.3 The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … wordfence
7422e7c6-fe0a-49be-ba9e-d14f66e328d0
< 1.16.17
MEDIUM 5.3 The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sens… wordfence
74160271-b27d-49fe-9550-e3949ecad048
< 2.7.3
MEDIUM 5.3 The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
73f0e8f0-88cd-4994-ad85-a0cf3e825a7b
< 4.13.0
MEDIUM 5.3 The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up … wordfence
73dd286e-5338-42d2-9928-1e14150ccf56
< 2.3.9
MEDIUM 5.3 The Button Generator – easily Button Builder plugin for WordPress is vulnerable to unauthorized modification of data d… wordfence
73d8135e-7324-4830-bb73-184b627d4106
< 2.3.2
MEDIUM 5.3 The CryptoCloud – Crypto Payment Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
73d188a5-97b4-4f54-8cb4-f26481ddcb56
< 1.1.21
MEDIUM 5.3 The SePay Gateway plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
73b4e081-caa8-4055-91e2-11979df20159
< 2.1.6
MEDIUM 5.3 The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to unautho… wordfence
739abe9a-bcc2-4014-8441-38b326802a70
< 3.3.8
MEDIUM 5.3 The Instantio – WooCommerce Quick Checkout | Direct Checkout, Floating Cart, Side Cart & Popup Cart plugin for WordPre… wordfence
7399f8f3-70ee-44ed-b8c8-211ae22aa86b
< 1.3.61
MEDIUM 5.3 The Contact Form Email plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and… wordfence
7391dd8c-0170-48c6-8451-9e7a00e268d0
< 2.0.7
MEDIUM 5.3 The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … wordfence
737aa726-b0df-47ac-aad1-0acf4bb1abdb
< 1.0.1.9
MEDIUM 5.3 The Gou Manage My Account Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … wordfence
73720e67-79e5-4b4c-8720-e28ad718b2b3
< 3.2.11
MEDIUM 5.3 The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missin… wordfence
7364f803-9808-4337-8922-2d7c88849361 MEDIUM 5.3 The Civi Framework plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
73643d45-9542-4372-a7a2-0a443819b8a2
< 2.33.1
MEDIUM 5.3 The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… wordfence
7363b5de-db30-4b35-b701-5c8f2835ec6c
< 4.4.8
MEDIUM 5.3 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access of data… wordfence
735b20ff-a708-4e1c-b96e-bcdec72aad95
< 20.8.11
MEDIUM 5.3 The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
73445d8f-1f9c-4ba7-9e3c-3e6221f3b23e
< 2.1.1
MEDIUM 5.3 The Bricksforge plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
7319293e-f921-46d1-aea6-2578d1a251a7
< 3.0.9
MEDIUM 5.3 The avalex – Automatisch sichere Rechtstexte plugin for WordPress is vulnerable to unauthorized modifcation of data du… wordfence
73163743-2bff-459d-bed9-593f6ce837fa
< 3.1.3
MEDIUM 5.3 WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canon… wordfence
72f3925d-6b3a-43bf-bfd1-fef7e71d5e43
< 8.6.01.005
MEDIUM 5.3 The WP Photo Album Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an… wordfence
72e92bd8-9060-4312-800c-e637e6881aa5 MEDIUM 5.3 The ShopSmart Loyalty for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions… wordfence
72baf0b2-48c1-437a-9570-9ecbaaca742a
< 4.3.0
MEDIUM 5.3 The Jobify - Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized access of functionality due to … wordfence
← Prev 1174 1175 1176 1177 1178 1179 1180 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top