πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1183 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6844c9a6-b25a-4ae1-96f6-023c1df80ddf
< 4.3.2
MEDIUM 5.3 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP… wordfence
68375862-a88a-4a37-a4e4-1c48b589db5c
< 2.4.1
MEDIUM 5.3 The picu – Online Photo Proofing Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a mi… wordfence
682e84f8-8dc4-4998-801c-8a58156c5b5b
< 6.8.2
MEDIUM 5.3 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Payment By… wordfence
681fd20b-6d89-4434-bf38-ccd2fa33a912 MEDIUM 5.3 The Upload Fields for WPForms – Drag and Drop Multiple File Upload, Image Upload, and Google Drive Upload for WPForms … wordfence
681e91a8-af2b-4b54-80a8-5886d681fc94
< 3.3.7
MEDIUM 5.3 The Peach Payments Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
6806e07b-96bf-43ad-a3ac-2105e7449e3c
< 1.2.20
MEDIUM 5.3 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosu… wordfence
67f9cce0-3ddb-48df-9d02-0c0d0105099e
< 2.17.14
MEDIUM 5.3 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Sensitive Information Exposure i… wordfence
67eef869-a57f-40b5-b289-9353bf5b680a MEDIUM 5.3 The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
67e7f95f-3c48-4a20-ba7f-e88fa565b451 MEDIUM 5.3 The Dokan Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
67b468f7-21c7-424a-a65c-172ef47f0465
< 1.1.0
MEDIUM 5.3 The package markdown-it 1.3.2 is vulnerable to Uncontrolled Resource Consumption in cases where special patterns with le… wordfence
67b36ed7-d7f4-4944-b721-219d1990971a
< 4.0.4.0
MEDIUM 5.3 The EventPrime plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
6788e2ee-ce61-494b-8d7f-6d1144466e58
< 1.1.5
MEDIUM 5.3 The WP Show Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
676b4637-a2c7-4a95-b644-bb0401f91b40
< 6.7.28
MEDIUM 5.3 The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions… wordfence
6763d445-0d4f-4ac0-b41a-a30e09fcb21c
< 3.0
MEDIUM 5.3 The LoginPress Pro plugin for WordPress is vulnerable to Captcha Bypass in versions up to, but not including, 3.0. This … wordfence
676346db-b861-408c-8fff-9b1c29167363 MEDIUM 5.3 The Job Board Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
67520500-fefd-45b6-9a32-9fd44af330d3 MEDIUM 5.3 The Tablesome Table Premium plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
6730f4a3-e915-434a-9f0a-2e96021915ac
< 3.1.0
MEDIUM 5.3 The Payment Gateway Based Fees and Discounts for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Objec… wordfence
66f6cae3-d38e-4ca3-82c5-606eb4a80c30 MEDIUM 5.3 The Jobica Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
66f29499-1522-43cd-af78-9b734c66af8c MEDIUM 5.3 The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
66e89753-f83e-4e60-b165-6d3d101d6c59
< 2.1
MEDIUM 5.3 The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including,… wordfence
66b1f539-9192-43f5-a77d-9763024e6b74
< 1.2.8
MEDIUM 5.3 The WP Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
66981560-c3d9-4533-b372-fad073d031f8 MEDIUM 5.3 The Sliced Invoices – WordPress Invoice Plugin plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
66849f80-45f0-4500-a058-1b30bd56b249 MEDIUM 5.3 The Featured Image Generator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
667870b0-916d-4add-a391-ffcc177a3757
< 7.0.0
MEDIUM 5.3 The Site Reviews plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.11.8 … wordfence
664b1362-c205-40b5-94b6-b32ca75dfe6d
< 1.0.9
MEDIUM 5.3 The HAPPY – Helpdesk Support Ticket System plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
← Prev 1180 1181 1182 1183 1184 1185 1186 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top