πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 27, 2026
Last Updated

40,383 vulnerabilities found (page 1191 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5898944f-565c-4950-83e8-ad0de0f948d1 MEDIUM 5.3 The PayTR Taksit Tablosu plugin for WordPress is vulnerable to improper authorization in versions up to, and including, … wordfence
58600bea-b7c1-4235-b051-13395ebab048
< 11.1.0
MEDIUM 5.3 The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulne… wordfence
58502e48-c1cf-4b94-954c-71046256c917 MEDIUM 5.3 The WP Forms Puzzle Captcha plugin for WordPress is vulnerable to Captcha Bypass in versions up to, and including, 2.8. … wordfence
582e2896-d800-4d73-8cef-8af76cba1ba8
< 7.95
MEDIUM 5.3 The DZS Video Gallery plugin for WordPress is vulnerable to remote/local file inclusion in versions up to, and excluding… wordfence
581e6686-a103-43f6-aa99-6a9862d98837
< 1.1.2
MEDIUM 5.3 The WP Child Theme Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… wordfence
581e1d70-0280-443b-b319-7047325866e4 MEDIUM 5.3 The Loginplus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
57ed9593-787c-41c0-abad-c70459e1d128
< 4.1.1
MEDIUM 5.3 The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval. wordfence
57b3eef3-e165-45ac-89d7-2a2a6529b310
< 2.7.31
MEDIUM 5.3 The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 v… wordfence
57ad3525-3257-4727-ba07-468bf13a94e2
< 1.0.4
MEDIUM 5.3 The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on … wordfence
57aacffa-0f49-4a33-ae40-d1c151363284
< 1.3.2
MEDIUM 5.3 The WooCommerce Clover Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a … wordfence
57a5b6d9-92dc-488a-a3f2-b3c09361aefe
< 1.9.41
MEDIUM 5.3 The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by s… wordfence
578892f2-9841-4493-8445-61b79feb4764
< 2.2.0.2
MEDIUM 5.3 The WP Popups – WordPress Popup builder plugin for WordPress is vulnerable to Full Path Disclosure in all versions up … wordfence
575edf4e-235d-4ad7-a6dd-3ffdbf4c71b5
< 2.6.25
MEDIUM 5.3 The Toolset Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl… wordfence
57473f14-0ed0-498b-a6d2-034e9646b049 MEDIUM 5.3 The Payment Button for PayPal plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including,… wordfence
57377380-0435-4747-abba-50063978d8e1
< 6.0.4.1
MEDIUM 5.3 The WP SMS plugin for WordPress is vulnerable to information disclosure via the REST API in versions up to, and includin… wordfence
572e290e-9324-4c17-8c3b-fa67233b15c4
< 6.1.3
MEDIUM 5.3 The WP STAGING Pro WordPress Backup Plugin for WordPress is vulnerable to Information Exposure in all versions up to and… wordfence
5727bc4e-ee92-4913-bc8f-3d002488b383
< 3.0.2
MEDIUM 5.3 The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, a… wordfence
56f3cb34-0452-4e3d-9442-0decc77f5e63
< 3.7.11
MEDIUM 5.3 The Ultimate Dashboard – Custom WordPress Dashboard plugin for WordPress is vulnerable to secret login page disclosure… wordfence
56e2b16e-68fa-421a-a69f-e22987580a47
< 2.0.74
MEDIUM 5.3 The Radio Player plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability … wordfence
56d0658c-b6b5-4e01-9f5b-a53dd4e380d8
< 5.7.0.1
MEDIUM 5.3 The LiteSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorizati… wordfence
56bb9034-879a-4788-8b8f-758dfcf0ecaf MEDIUM 5.3 The Woostify Sites Library plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
56b6b56d-7ff4-40b5-a34b-703088387ab1 MEDIUM 5.3 The User Verification plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and incl… wordfence
56b4d824-96b8-40e6-97b5-17748d13574a
< 4.5.26
MEDIUM 5.3 The Helpful plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 4.5.25. Spec… wordfence
566b8fd0-4034-4eb5-b344-a4f45aa08ba4
< 1.7.3
MEDIUM 5.3 The Product Configurator for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in version… wordfence
565980d7-8dc9-42a4-90c5-2f75af52fb8e
< 6.2.9
MEDIUM 5.3 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… wordfence
← Prev 1188 1189 1190 1191 1192 1193 1194 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top