πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1188 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5f24313e-c246-44f8-b144-d95c55e71456
< 19.9.8
MEDIUM 5.3 The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to Information … wordfence
5f1a861b-43d6-4315-9ec4-802dbae32f43
< 1.7.9
MEDIUM 5.3 The MC Woocommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
5f07558d-6e40-4afb-82a1-c9482534d6dd
< 2.0.20
MEDIUM 5.3 The Payment Plugins for PayPal WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, a… wordfence
5efe6f9b-6b92-44a7-8728-fa91d2341136
< 9.2.07.002
MEDIUM 5.3 The Photo Album Plus plugin for WordPress is vulnerable to Arbitrary Zip File Deletion in versions up to, and including,… wordfence
5ec6211b-783b-4375-972b-adcaf9f9f526
< 1.5.1
MEDIUM 5.3 The Easy Author Image plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.… wordfence
5ec23f29-baa3-4bfc-a7b7-d664a81637c1
< 4.16.6
MEDIUM 5.3 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access due to… wordfence
5ebe8caf-6963-4ed0-8552-62513bb0e947
< 6.7.4
MEDIUM 5.3 The PenNews - Multi-Purpose AMP WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missin… wordfence
5e822372-4f38-4b2a-b1d6-5a095ecb716f
< 4.22
MEDIUM 5.3 The AFS Analytics plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
5e6797a4-9b2d-44a2-bfe5-354e8885a47b MEDIUM 5.3 The WordPress Booking Plugin – TheBooking plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
5e274781-1c20-4224-bc10-26dadb9b1e07
< 2.4.10
MEDIUM 5.3 The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Veri… wordfence
5e1950c7-cc7c-48cf-974e-f691ef61d6be
< 1.3.2
MEDIUM 5.3 The AForms Eats plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.3.1. … wordfence
5e0767a8-9e82-4ce4-9df9-19b458dc5ce0
< 1.4.7
MEDIUM 5.3 The eRoom – Zoom Meetings & Webinar plugin for WordPress is vulnerable to retrieve setting information due to a missin… wordfence
5df9019a-e87a-42c6-a71a-d71a1c415d6c MEDIUM 5.3 The Royale News theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
5df4b4ed-14ec-4895-9d84-9edb5311b78c
< 8.2.2
MEDIUM 5.3 The PayPlus Payment Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
5df32365-5381-48e0-9313-7e83c4c6c440
< 2.1.6
MEDIUM 5.3 The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
5dc278a9-79bd-4494-a34c-a5e92cde7062
< 2.2.1
MEDIUM 5.3 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Sensitive Information … wordfence
5db4709d-0121-4b37-b0d2-79aa7943b442
< 4.1.4
MEDIUM 5.3 The HitPay Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all v… wordfence
5db3c66f-0a9c-4233-923c-0965dec68c60
< 2.0.9
MEDIUM 5.3 The FundPress – WordPress Donation Plugin for WordPress is vulnerable to authorization bypass in versions up to and in… wordfence
5db195c1-8917-4465-a5ca-21089afb0bc7
< 4.8.6
MEDIUM 5.3 The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o… wordfence
5da29ff7-0e9d-487b-8f12-cd9912198cba MEDIUM 5.3 The Blog Designer PRO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
5d50e9bb-e357-42d3-b131-468511b8e98a
< 1.4.4
MEDIUM 5.3 The Send Users Email plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… wordfence
5d208a43-dd4f-4625-9584-5ce585c7c1ce
< 1.9.6
MEDIUM 5.3 The Delicious plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
5d1e5030-fb78-47da-b571-048b97c9ff9e
< 1.3.0
MEDIUM 5.3 The WPCasa plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, … wordfence
5d106394-0dad-4d96-9063-6824fce65bdd
< 1.5.3
MEDIUM 5.3 The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2… wordfence
5cfc38c0-f940-4c4d-ba7b-0d772146ea2d
< 1.3
MEDIUM 5.3 The Preloader for Website plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
← Prev 1185 1186 1187 1188 1189 1190 1191 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top