πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1190 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5ad275a2-c559-4a2f-8f82-646cb75285a7
< 1.0.20
MEDIUM 5.3 The Htaccess File Editor – Easily Edit, Backup, Restore .htaccess file plugin for WordPress is vulnerable to Sensitive… wordfence
5ac7455a-0c89-4f5b-84eb-b7cc87bce8d4 MEDIUM 5.3 The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure… wordfence
5abc012f-b728-43e1-b6f4-2fc2bb753548
< 1.5.1
MEDIUM 5.3 The WP Directory Kit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… wordfence
5a98483c-d75e-45a4-bc67-a2fe330cd1c9 MEDIUM 5.3 The Cartify - WooCommerce Gutenberg WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a mi… wordfence
5a801ea0-725f-4da4-bed2-6798f403c0ae
< 2.1.18.1
MEDIUM 5.3 The JetWooBuilder for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
5a3c16a5-65e5-4fe9-b7f0-2e021534c054
< 2.2.22
MEDIUM 5.3 The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up… wordfence
5a38a72a-7336-4aa5-8491-6879dfa4d0ea MEDIUM 5.3 The User Activity plugin for WordPress is vulnerable to IP Address Spoofing in versions up to and including 1.0.1. This … wordfence
5a334947-296d-4f26-95e1-594487e8b6c8
< 1.10.6
MEDIUM 5.3 The Broken Link Checker plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1… wordfence
5a1dc947-f117-4bb0-bf39-f49ba0874d51 MEDIUM 5.3 The Macro Calculator with Admin Email Optin & Data plugin for WordPress is vulnerable to Sensitive Information Exposure … wordfence
5a1b31f4-5594-4179-a88d-11167b58d96c
< 3.7.8
MEDIUM 5.3 The Popup Like box plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
5a1391b1-b0c3-4cf4-8850-d9367d90ec9e
< 2.11.29
MEDIUM 5.3 The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
59ff476d-466f-4b2e-b867-342127a67901
< 3.3.0
MEDIUM 5.3 The Add Expires Headers & Optimized Minify plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
59da92e2-9ea0-4566-ae4d-3d5d91d0e42e MEDIUM 5.3 The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu… wordfence
59c0caa2-d0c2-472e-83c3-d11ad313720d
< 2.0.8
MEDIUM 5.3 The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo… wordfence
598875c5-65f4-4512-bf76-a9c02fc16992
< 1.2.3
MEDIUM 5.3 The Masterstudy Elementor Widgets plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
5981b937-189f-4dc3-baf0-ee0d194229eb
< 4.16.6
MEDIUM 5.3 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access due to… wordfence
596f70da-6dd6-4c2b-8d34-bff87d53faeb MEDIUM 5.3 The Cream Blog theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
595d6cdb-8a42-480e-8b04-52998156488c
< 1.12.11
MEDIUM 5.3 The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin f… wordfence
594fc4c4-6215-4cbc-b33b-1eb2ca7b4bc5
< 2.16.13
MEDIUM 5.3 The eShipper Commerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
5947f7cb-de84-4a62-bef7-cbeb1f20bb72 MEDIUM 5.3 The Flexible Woocommerce Checkout Field Editor plugin for WordPress is vulnerable to unauthorized access due to a missin… wordfence
594753c7-56fd-42fe-9ccd-a614e4f71cee
< 1.6.1
MEDIUM 5.3 The Smart Online Order for Clover plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u… wordfence
593b2ea2-0627-45ce-b672-cc815bff338b
< 2.2.27
MEDIUM 5.3 The Glossary plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.26. Th… wordfence
593299e5-d9eb-4240-8413-c0fe5ab79d82
< 4.24.0
MEDIUM 5.3 The Sensei LMS and Sensei Pro (WC Paid Courses) plugins for WordPress is vulnerable to unauthorized modification of data… wordfence
59178e0f-1bf3-4208-a14e-d0cac0de8dbd
< 1.3.93
MEDIUM 5.3 The Appointment Booking Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
59170f0a-975e-487c-bdb0-585c802b3127
< 1.8.2
MEDIUM 5.3 The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … wordfence
← Prev 1187 1188 1189 1190 1191 1192 1193 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top