πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1184 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6647856b-19f2-475a-8d45-d33c7b3a8f92
< 3.5.4
MEDIUM 5.3 The Easy Property Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
664187f0-d49c-4876-bed0-ce169a2ec89a MEDIUM 5.3 The MeetingHub – Webinar & Meeting Plugin for Zoom, Google Meet, Webex, Microsoft Teams, & Jitsi Meet plugin for WordP… wordfence
662fcf6c-1095-4cea-949f-91af8fba1e47
< 3.1
MEDIUM 5.3 The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to Sensitive Inform… wordfence
66122be6-7c28-44cc-a8dd-7b2ec64346f7
< 4.2.1
MEDIUM 5.3 The Defender Security – Malware Scanner, Login Security & Firewall plugin for WordPress is vulnerable to security feat… wordfence
660fa0d6-1325-4599-b146-47561c15b5fd
< 4.21.0
MEDIUM 5.3 The MStore API plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
65ca20b0-0831-4f60-9021-679be6c145ef
< 3.3.7
MEDIUM 5.3 The Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin for WordPress is vulnerable to A… wordfence
65c45519-97c8-4869-bd23-ac611f5a457b
< 4.0.16
MEDIUM 5.3 The Ultimate Post Kit Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up… wordfence
65aa6694-0ed9-40a4-bd1c-1b51cd5e537d MEDIUM 5.3 The THE Leads Management System: 59sec LITE plugin for WordPress is vulnerable to authorization bypass due to a missing … wordfence
65a0033d-2266-429c-aab2-80bd46c93b91
< 2.1.3
MEDIUM 5.3 Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin… wordfence
65963ce0-6589-4753-837c-14ef37a1a9e3
< 1.2.7
MEDIUM 5.3 The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl… wordfence
6576aa18-0f30-407b-a651-127d216097f5
< 2.7.10
MEDIUM 5.3 The SumUp Payment Gateway For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
6567e63c-3129-47b2-a734-733eb599821a
< 6.0.2
MEDIUM 5.3 The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includ… wordfence
6560bec0-286a-499e-a3d8-98596e16c83b
< 3.4.2
MEDIUM 5.3 The Houzez theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in a… wordfence
6554a95c-13f9-4548-a062-fe9cd873d334
< 9.6.0.1
MEDIUM 5.3 The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to unauthorized acces… wordfence
6551eea6-1059-4caa-876c-3d08083130f6
< 3.6.26
MEDIUM 5.3 The Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on t… wordfence
653bf021-370d-4787-9ded-c5c915aed1d6
< 1.0.9
MEDIUM 5.3 The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and includi… wordfence
652f7cb3-dc5a-4071-a605-0ea65beeb06c
< 3.1.4
MEDIUM 5.3 The Events Made Easy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inclu… wordfence
64c2c8c2-58f5-4b7d-b226-39ba39e887d5
< 2.2.11
MEDIUM 5.3 The WP Club Manager – WordPress Sports Club Plugin plugin for WordPress is vulnerable to unauthorized modification of … wordfence
64bc7d47-6b63-4fd9-85d4-82126f86308a
< 2.8.7
MEDIUM 5.3 The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and inclu… wordfence
64889659-24d6-40d9-97ba-b448f5205a96
< 5.22.0
MEDIUM 5.3 The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to… wordfence
6483ba93-d9ae-44a1-a4fc-b3b4af5ac36f MEDIUM 5.3 The Cryptocurrency Donation Box – Bitcoin & Crypto Donations plugin for WordPress is vulnerable to unauthorized access… wordfence
646e75be-716e-4336-80c4-d268e9565c5a
< 1.1.3
MEDIUM 5.3 The WooCommerce Quick View plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… wordfence
646b853e-7748-4598-b0b4-feeb17f64235
< 3.1.5
MEDIUM 5.3 The Vitepos – Point of sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due… wordfence
645328f3-2bcb-4287-952c-2e23ec57bb4e
< 6.1.7
MEDIUM 5.3 The WP Maintenance plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.1.… wordfence
64292fc7-8f74-4515-988b-f803b0fd7494
< 1.6.12.6
MEDIUM 5.3 The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up t… wordfence
← Prev 1181 1182 1183 1184 1185 1186 1187 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top