πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1179 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
715dc265-253e-4409-b57d-474d3740adbe
< 4.5.6
MEDIUM 5.3 Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to ve… wordfence
7158ed57-37b4-43ac-b323-46febaaccffc
< 7.6.44
MEDIUM 5.3 The Comments – wpDiscuz plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … wordfence
714acd7d-6d19-4087-bb27-b9a4ccbb678b
< 1.5.113
MEDIUM 5.3 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address … wordfence
713bbae4-c037-47fc-b0c7-71667232de7b
< 1.4.48
MEDIUM 5.3 The Support Genix Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
7129d8cf-6b7d-4b7b-bd6a-85176247ab29 MEDIUM 5.3 The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to… wordfence
7126e39a-f3aa-4815-b039-485995d6bba3 MEDIUM 5.3 The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensiti… wordfence
71257639-2ba5-4ac2-b4fe-8f22311b6482
< 1.2.0
MEDIUM 5.3 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to unauthorized access du… wordfence
712535ce-8c38-4944-aa0a-36d9bacaeb67
< 5.9.7.3
MEDIUM 5.3 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object R… wordfence
7100927e-fbcc-44ed-b7e1-475a5692c173
< 1.0.43
MEDIUM 5.3 The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
70ed8cfb-845c-4015-a855-69f6577ccad9
< 3.12.28
MEDIUM 5.3 The Easy Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and … wordfence
70da8039-6526-47fa-934d-53fa29ca1bf0
< 0.20.8
MEDIUM 5.3 The Tainacan plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST… wordfence
70b56b64-2334-44f1-9924-1ea642664b41
< 8.3.10
MEDIUM 5.3 The Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator plugin for WordPress is vulnerable to unauth… wordfence
70a93afa-9801-41d2-8923-ca4ae6ae974f
< 2.1.15
MEDIUM 5.3 The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … wordfence
7076c253-91ac-46b4-91ad-89a296408959
< 1.5.3
MEDIUM 5.3 The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2… wordfence
7072b93b-4d18-464e-802d-a6c17a224593
< 1.7.20
MEDIUM 5.3 The Shared Files – Advanced File Sharing & Download Manager with Frontend Uploads & Lead Generation plugin for WordPre… wordfence
705823ff-e9c3-4b8b-b71c-3b60d0d15b01
< 2.3.6
MEDIUM 5.3 The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in … wordfence
702261eb-4f85-4388-9f82-75476640e8ed
< 2.2.7
MEDIUM 5.3 The AForms β€” Form Builder for Price Calculator & Cost Estimation plugin for WordPress is vulnerable to Full Path Discl… wordfence
701a037d-bbd5-436d-bfc8-394c9dcf6bab
< 2.1.1
MEDIUM 5.3 The Bricksforge plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the a fun… wordfence
7012b34d-8d65-4575-9965-417739206b5f
< 4.0
MEDIUM 5.3 The Protect WP Admin plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 3.8.… wordfence
6ffccb84-faee-4a47-ab49-dbbb4858a6a5
< 2.21.5
MEDIUM 5.3 The Tourfic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
6fe31cc9-dcf8-480b-bc90-2c9ca91fabb3
< 1.17.3
MEDIUM 5.3 The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to un… wordfence
6fd6cb72-c508-46b1-99fb-cbd6b12b45de
< 1.3.9
MEDIUM 5.3 The Stop User Enumeration plugin for WordPress is vulnerable to Username Enumeration in versions up to, and including, 1… wordfence
6fd46539-a55e-45ab-93b2-6a1703a91271
< 1.3.6.5
MEDIUM 5.3 The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to File Upload Size Limit B… wordfence
6fd3ea16-4706-4573-b905-93dff434968d
< 3.3.6
MEDIUM 5.3 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in a… wordfence
6fb00ce4-aa82-4479-b7f6-79e7bde098c1
< 4.3.2.5
MEDIUM 5.3 The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to,… wordfence
← Prev 1176 1177 1178 1179 1180 1181 1182 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top