🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1189 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5ce039db-b597-4bbf-8067-933a262ae1b6
< 2.0.2
MEDIUM 5.3 The WP Job Portal plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
5cd8c464-1402-4301-ac66-4e6fc0328de2
< 1.2.17
MEDIUM 5.3 The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to Insecure Direct Object R… wordfence
5cd0e015-abf2-4905-8b42-46b685be2c74
< 3.7.4.1
MEDIUM 5.3 The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPre… wordfence
5cc5662e-a9c3-4a15-bf68-0ec5835d3f3b
< 3.8.6
MEDIUM 5.3 The WP-Lister Lite for eBay plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
5c71dc22-0b1b-4628-bbab-4154714e8804
< 1.6.21
MEDIUM 5.3 The weForms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the handle_fr… wordfence
5c408a27-7ed9-4106-8b65-9169ecc0e6f5 MEDIUM 5.3 The NextGen Cu3er Gallery plugin for WordPress is vulnerable to Multiple Full Path Disclosures in versions up to, and in… wordfence
5c394739-14c9-4e62-985b-3791f48dca65
< 1.17.18
MEDIUM 5.3 The AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available) plugin for WordPress is vulnerabl… wordfence
5c1e6685-44a7-452e-89ab-b9fffb65a12b
< 2.4.2
MEDIUM 5.3 The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in v… wordfence
5bfd1650-0cc1-4b1c-9fc2-c940d841a147
< 1.5.2
MEDIUM 5.3 WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/v… wordfence
5be1b4b2-4b33-45d7-82fd-b4d51e16535c
< 1.5.14
MEDIUM 5.3 The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details. wordfence
5be01bba-e4f4-4818-9612-fc37b648a349 MEDIUM 5.3 The Cart66 Cloud plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… wordfence
5bcdfac0-6bca-40da-899c-44bcaa71af13
< 2.9.13
MEDIUM 5.3 The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec… wordfence
5baea929-0c46-4a43-b2af-367c0b5037bb
< 3.3.6
MEDIUM 5.3 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of da… wordfence
5ba7a54d-3497-4788-aa73-081d2c1015fc MEDIUM 5.3 The 404 Error Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
5b957f8a-6720-484f-bfb0-b1bf7b0e03da
< 4.2.23
MEDIUM 5.3 The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to Sensitive Infor… wordfence
5b80638b-4dd1-47f5-9a70-6bd626ac6986 MEDIUM 5.3 The Subway – Private Site Option plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions … wordfence
5b7b3286-b36d-42c6-94e8-e8c24047c472
< 3.8.0
MEDIUM 5.3 The POS Entegratör – Gurmehub Ödeme Eklentisi plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
5b680158-0752-46bd-a5bb-343b65c0aeb4
< 1.0.34
MEDIUM 5.3 The Tablesome – Responsive Table, Woocommerce Automation, Email Log, Form Automation – Contact Form 7, Elementor, WP… wordfence
5b611abb-460c-44d4-9f77-052a208f8d85
< 1.6.29
MEDIUM 5.3 The Booking Package plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 1.6.2… wordfence
5b5c2a74-c1e8-4381-8d0d-66a2ed3b937e
< 4.2.13
MEDIUM 5.3 The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions availabl… wordfence
5b3aca44-0d47-4285-93e5-5cf147b5800e
< 2.1.12
MEDIUM 5.3 The Arconix Shortcodes plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… wordfence
5b35a3af-acd4-40e3-9fdd-25e2f046af7b
< 4.2.2
MEDIUM 5.3 The Contextual Related Posts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
5b266a09-22f3-4ac3-a2ba-8321503200e7
< 1.2.7
MEDIUM 5.3 The JVM WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'user_id' pa… wordfence
5b2553b9-775a-48f4-a7fd-1b885511bfa9 MEDIUM 5.3 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Insecure Direct Object Reference … wordfence
5b05e973-c0ab-492f-8b51-e7c2f33475ad
< 1.0.4
MEDIUM 5.3 The Leads5050 Visitor Insights plugin for WordPress is vulnerable to Arbitrary License Change in versions before 1.0.4. … wordfence
← Prev 1186 1187 1188 1189 1190 1191 1192 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top