πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1187 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
60878165-d4cc-4ea1-acf7-9bb6fd48795b
< 2.10.3
MEDIUM 5.3 The W3 Total Cache plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.10.2. Th… wordfence
605dc24c-5b6e-479b-98dd-ad80c547824c
< 1.13.20
MEDIUM 5.3 The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19.… wordfence
605c9d35-886a-4abe-82ce-fee4a2dda611
< 2.0.0
MEDIUM 5.3 The ModelTheme Framework plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
6054e4fe-b10e-4c63-877d-05d6662a9251
< 8.7.14
MEDIUM 5.3 The Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons plugin for WordPress … wordfence
6049996a-514a-44f7-9878-4aa43598842a
< 2.13.1
MEDIUM 5.3 The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13.… wordfence
6047c648-1999-4333-9be9-abe0c17328fb
< 2.1.61
MEDIUM 5.3 The Job Board Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
6041b564-62d1-49bf-a3f7-f4b01d1b5a89
< 4.3.2
MEDIUM 5.3 The Order Delivery Date for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
60379757-fe43-4a76-a65a-ee09163dab0a
< 1.3.21
MEDIUM 5.3 The SMTP Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3… wordfence
6030f7e5-cb2d-465b-b58b-7339b35055a9 MEDIUM 5.3 The Clear Sucuri Cache plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
602df370-cd5b-46dc-a653-6522aef0c62f
< 6.5.2.5
MEDIUM 5.3 The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th… wordfence
60083262-198d-4a7d-bb0a-717a744e20f9
< 1.2.7
MEDIUM 5.3 The WP Directory Kit plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capabil… wordfence
5fcf9a7f-e48c-40a7-9af8-6a2e631ef6e3
< 3.2.1
MEDIUM 5.3 The New User Approve plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
5fb338c2-f458-42bc-b147-d5024875e977
< 3.2.10
MEDIUM 5.3 The Sunshine Photo Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on s… wordfence
5fa75f3a-3582-4851-a67c-6c4981fb9abb
< 3.1.3
MEDIUM 5.3 The Templately – Elementor & Gutenberg Template Library: 5000+ Free & Pro Ready Templates & Cloud! plugin for WordPres… wordfence
5f9d237c-110e-4e71-9d2c-db99358468e6
< 3.1.0
MEDIUM 5.3 The Autoptimize plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3… wordfence
5f9cece7-a158-41ae-816b-1054da830724
< 3.2.83
MEDIUM 5.3 The Download Manager plugin for WordPress is vulnerable to information Exposure in all versions up to, and including, 3.… wordfence
5f9301dc-87c5-400c-8832-c50124cc748a
< 2.5.1
MEDIUM 5.3 The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of d… wordfence
5f902f32-342e-4d5c-9c2c-4ee682248b8a
< 3.30
MEDIUM 5.3 The Media Library Assistant plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
5f843d64-09eb-4e75-9e45-cd0cec580e60 MEDIUM 5.3 The Responsive Google Map plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
5f83c19e-1b75-4fea-b4de-f7f844a449c0
< 2.2.24
MEDIUM 5.3 The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for Word… wordfence
5f7b9673-e1a3-4e51-9fcb-3ba86d7656b5 MEDIUM 5.3 The Simple Website Logo plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
5f70a523-dbb0-4c32-95b5-aee1f5aada21 MEDIUM 5.3 The Multi-language Responsive Contact Form plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
5f6c0e18-6a6b-40c5-95be-87fc7d49ae92
< 1.1.42
MEDIUM 5.3 The Hydra Booking β€” Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized acces… wordfence
5f3c6d98-6f30-4a98-91c9-e77c1f960527
< 4.6.2
MEDIUM 5.3 The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
5f388049-b453-406c-abdf-2a51c7abed2d
< 1.2.17
MEDIUM 5.3 The iQ Block Country WordPress plugin through 1.2.13 does not properly checks HTTP headers in order to validate the orig… wordfence
← Prev 1184 1185 1186 1187 1188 1189 1190 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top